Tech

Another major WordPress plugin has been hacked to try and hijack your sites

Share
Share


  • Researchers from WPScan find flaw in Hunk Companion, a plugin with roughly 10,000 users
  • The flaw allows crooks to install other plugins from the WP repository, including those with known RCE flaws
  • WPScan found the flaw while investigating an active attack

Hackers have reportedly found a way to install old, outdated, and vulnerable plugins on WordPress websites, directly from the WordPress plugin repository. That way, they are able to introduce vulnerabilities to target sites made with the website builder, which grant them remote code execution (RCE) abilities, SQL injection, cross-site scripting (XSS), admin account creation, and more.

The bug that allows crooks to do that was found in Hunk Companion, a utility plugin designed to enhance the functionality of WordPress themes developed by ThemeHunk.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
South Korea’s LG Energy Solution exits from .4bn Indonesia project
Tech

South Korea’s LG Energy Solution exits from $8.4bn Indonesia project

Credit: Unsplash/CC0 Public Domain South Korea’s LG Energy Solution said Tuesday it...

The Oscars’ new AI rule provides a tentative green light for generative tech in movies
Tech

The Oscars’ new AI rule provides a tentative green light for generative tech in movies

Ahead of the 98th Oscars ceremony, scheduled for March 2026, the Academy...

US urges curb of Google’s search dominance as AI looms
Tech

US urges curb of Google’s search dominance as AI looms

Google contends the US is overreaching by asking a federal judge to...

Auto Shanghai to showcase electric competition at sector’s new frontier
Tech

Auto Shanghai to showcase electric competition at sector’s new frontier

The Shanghai auto show is the world’s biggest and will showcase some...