instawp Vulnerabilities and Affected Products
Vulnerabilities associated with instawp_connect.
Products
Clear product- InstaWP Connect10 vulnerabilities
- InstaWP Connect – 1-click WP Staging & Migration7 vulnerabilities
- instawp_connect7 vulnerabilities
- String locator3 vulnerabilities
- Connect - 1-click WP Staging & Migration plugin for WordPress1 vulnerability
- Connect 1-click WP Staging & Migration Plugin for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-2636HIGH | InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File InclusionThe InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file types can be upl… | CVSS8.1v3.1 | EPSS10.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-6397CRITICAL | InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.44 - Authentication Bypass to AdminThe InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username, and to perform a variety of other administrative tasks. NOTE: This vulnerability was partially fixed in 0.1.0.44, but was … | CVSS9.8v3.1 | EPSS0.706% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37228CRITICAL | WordPress InstaWP Connect plugin <= 0.1.0.38 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38. | CVSS10.0v3.1 | EPSS0.531% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22145HIGH | WordPress InstaWP Connect plugin <= 0.1.0.8 - Arbitrary Option Update to Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | CVSS8.8v3.1 | EPSS1.11% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-25918CRITICAL | WordPress InstaWP Connect plugin <= 0.1.0.8 - Remote Code Execution vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | CVSS9.9v3.1 | EPSS0.681% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23507HIGH | WordPress InstaWP Connect plugin <= 0.1.0.9 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. CWE-89Jan 31, 2024 | CVSS8.5v3.1 | EPSS0.621% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23506HIGH | WordPress InstaWP Connect plugin <= 0.1.0.9 - Sensitive Data Exposure vulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. | CVSS7.7v3.1 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |