PT-2024-34276 · WordPress · Hunk Companion+1
Stealthcopter
·
Published
2024-10-28
·
Updated
2026-01-23
·
CVE-2024-50498
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WP Query Console versions n/a through 1.0
Hunk Companion versions prior to 1.9.0
Description:
The issue is related to an Improper Control of Generation of Code ('Code Injection') vulnerability, which allows code injection. This vulnerability affects WP Query Console and can be used to execute commands on the target website, potentially leading to backdoor access and full control over the website. According to WPScan, hackers have been using vulnerabilities in Hunk Companion and WP Query Console plugins to gain permanent backdoor access to vulnerable WordPress websites. Approximately 90% of the 10,000 installations of the Hunk Companion plugin are reportedly still running on unpatched versions. Defiance has blocked over 56,000 attacks targeting the Hunk Companion vulnerability in the last 24 hours.
Recommendations:
For WP Query Console versions n/a through 1.0: Immediate deactivation and uninstallation are recommended.
For Hunk Companion versions prior to 1.9.0: Update to version 1.9.0 as soon as possible and check the site for signs of intrusion, including the installation of WP Query Console or other plugins.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hunk Companion
Wp Query Console