← WordPress Vulnerabilities
WordPress security by component

Hunk Companion

Hunk Companion is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Dec 31, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: hunk-companion

CVE-2024-11972: Hunk Companion: A security weakness

Hunk Companion is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedDec 31, 2024
Safe version guidanceSee mitigation notes
Safe version
Dec 31, 2024 CVE-2024-11972
Hunk Companion: A security weakness
Hunk Companion is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Oct 11, 2024 CVE-2024-9707
Hunk Companion: Code execution
Hunk Companion is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending