From fbce62d41caa52fd1ade966aea40f8cc83002fcd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 31 Dec 2024 06:32:20 +0000 Subject: [PATCH] Publish GHSA-pp53-3m4v-vvmw --- .../GHSA-pp53-3m4v-vvmw.json | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-pp53-3m4v-vvmw/GHSA-pp53-3m4v-vvmw.json diff --git a/advisories/unreviewed/2024/12/GHSA-pp53-3m4v-vvmw/GHSA-pp53-3m4v-vvmw.json b/advisories/unreviewed/2024/12/GHSA-pp53-3m4v-vvmw/GHSA-pp53-3m4v-vvmw.json new file mode 100644 index 00000000000..d98dea7e73a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pp53-3m4v-vvmw/GHSA-pp53-3m4v-vvmw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp53-3m4v-vvmw", + "modified": "2024-12-31T06:30:54Z", + "published": "2024-12-31T06:30:54Z", + "aliases": [ + "CVE-2024-11972" + ], + "details": "The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11972" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4963560b-e4ae-451d-8f94-482779c415e4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T06:15:23Z" + } +} \ No newline at end of file