Source |
The Hacker News |
Identifiant |
8623961 |
Date de publication |
2024-12-12 14:48:00 (vue: 2024-12-12 11:08:04) |
Titre |
WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins |
Texte |
Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks.
The flaw, tracked as CVE-2024-11972 (CVSS score: 9.8), affects all versions of the plugin prior to 1.9.0. The plugin has over 10,000 active installations.
"This flaw poses a significant security risk, as it
Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks.
The flaw, tracked as CVE-2024-11972 (CVSS score: 9.8), affects all versions of the plugin prior to 1.9.0. The plugin has over 10,000 active installations.
"This flaw poses a significant security risk, as it |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
000 11972 2024 active actors affects all are attacks companion could critical cve cvss door exploited exploiting flaw has hunk install installations malicious open other over plugin plugins poses prior risk score: security significant silently tracked variety versions vulnerability vulnerable wordpress |
Tags |
Vulnerability
|
Stories |
|
Move |
|