Threat Advisory

Critical Vulnerability in Hunk Companion WordPress Plugin Exposes Sites

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A critical vulnerability in the Hunk Companion plugin for WordPress has been discovered, allowing attackers to perform arbitrary plugin installations via unauthenticated POST requests. This flaw affects all versions of Hunk Companion before, which addresses the issue. The vulnerability has been actively exploited to compromise WordPress sites, including using the exploit to install a vulnerable version of WP Query Console and leveraging a remote code execution flaw to gain persistent backdoor access. Attackers have been observed writing PHP droppers to site root directories, enabling continued unauthenticated uploads. Despite patches, attackers have found ways to bypass them, making immediate updating crucial to mitigate the risk. At the time of writing, many websites remain vulnerable, highlighting the importance of prompt action to protect site security. Additionally, users are encouraged to audit their sites for suspicious activity and remove any malicious files to prevent further exploitation.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A critical vulnerability in the Hunk Companion plugin for WordPress has been discovered, allowing attackers to perform arbitrary plugin installations via unauthenticated POST requests. This flaw affects all versions of Hunk Companion before, which addresses the issue. The vulnerability has been actively exploited to compromise WordPress sites, including using the exploit to install a vulnerable version of WP Query Console and leveraging a remote code execution flaw to gain persistent backdoor access. Attackers have been observed writing PHP droppers to site root directories, enabling continued unauthenticated uploads. Despite patches, attackers have found ways to bypass them, making immediate updating crucial to mitigate the risk. At the time of writing, many websites remain vulnerable, highlighting the importance of prompt action to protect site security. Additionally, users are encouraged to audit their sites for suspicious activity and remove any malicious files to prevent further exploitation.[emaillocker id="1283"]

  • CVE-2024-11972: It is a critical vulnerability in the Hunk Companion WordPress plugin, affecting versions prior to. It allows unauthenticated attackers to install arbitrary plugins via POST requests. The flaw has been actively exploited to deploy vulnerable plugins like WP Query Console, enabling remote code execution. Users should urgently update to secure their websites.
  • CVE-2024-50498: It is a remote code execution (RCE) vulnerability in the outdated WP Query Console WordPress plugin. Exploited in active attacks, it allows malicious PHP code execution on targeted sites. Attackers leverage this flaw to install backdoors, ensuring persistent unauthorized access. Updating or removing the vulnerable plugin is essential to mitigate the risk.
  • CVE-2024-9707: It is a vulnerability in the Hunk Companion WordPress plugin that was addressed. It allows attackers to bypass authentication and exploit flaws for unauthorized plugin installations. The patch for this issue proved insufficient, leaving room for exploitation through bypass methods. Users must update to the version to ensure comprehensive protection.

RECOMMENDATION:

We strongly recommend you update Hunk Companion Plugin to version 1.9.1.

 

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hunk-companion-wordpress-plugin-exploited-to-install-vulnerable-plugins/

[/emaillocker]
crossmenu