Known CVE
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
The plugin does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the WordPress.org repo, including vulnerable plugins that have been closed.
CVE-2024-11972
Critical2024CVSS 9.8
cve2024 · wordpress · wp · wp-plugin · hunk-companion · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website