EXECUTIVE SUMMARY:
A critical vulnerability in the Hunk Companion plugin for WordPress has been discovered, allowing attackers to perform arbitrary plugin installations via unauthenticated POST requests. This flaw affects all versions of Hunk Companion before, which addresses the issue. The vulnerability has been actively exploited to compromise WordPress sites, including using the exploit to install a vulnerable version of WP Query Console and leveraging a remote code execution flaw to gain persistent backdoor access. Attackers have been observed writing PHP droppers to site root directories, enabling continued unauthenticated uploads. Despite patches, attackers have found ways to bypass them, making immediate updating crucial to mitigate the risk. At the time of writing, many websites remain vulnerable, highlighting the importance of prompt action to protect site security. Additionally, users are encouraged to audit their sites for suspicious activity and remove any malicious files to prevent further exploitation.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical vulnerability in the Hunk Companion plugin for WordPress has been discovered, allowing attackers to perform arbitrary plugin installations via unauthenticated POST requests. This flaw affects all versions of Hunk Companion before, which addresses the issue. The vulnerability has been actively exploited to compromise WordPress sites, including using the exploit to install a vulnerable version of WP Query Console and leveraging a remote code execution flaw to gain persistent backdoor access. Attackers have been observed writing PHP droppers to site root directories, enabling continued unauthenticated uploads. Despite patches, attackers have found ways to bypass them, making immediate updating crucial to mitigate the risk. At the time of writing, many websites remain vulnerable, highlighting the importance of prompt action to protect site security. Additionally, users are encouraged to audit their sites for suspicious activity and remove any malicious files to prevent further exploitation.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Hunk Companion Plugin to version 1.9.1.
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hunk-companion-wordpress-plugin-exploited-to-install-vulnerable-plugins/