Exploitation of WordPress Hunk Companion Plugin Vulnerability Leads to Stealthy Installation of Insecure Plugins
A critical vulnerability in the WordPress Hunk Companion plugin has been identified, allowing malicious actors to install additional vulnerable plugins and create pathways for attacks. This flaw, designated as CVE-2024-11972 with a CVSS score of 9.8, impacts all versions preceding 1.9.0 and affects over 10,000 active installations, heightening security risks…