CVE-2024-2667
CRITICAL EXPLOITED NUCLEIInstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
Title source: nucleiDescription
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.
Exploits (3)
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-2667-Poc
Nuclei Templates (1)
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
CRITICALVERIFIEDby DhiyaneshDK
FOFA:
body="/wp-content/plugins/instawp-connect/"
References (2)
Scores
CVSS v3
9.8
EPSS
0.9014
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2024-04-12
Classification
CWE
CWE-434
Status
published
Affected Products (1)
instawp/instawp_connect
< 0.1.0.23
Timeline
Published
May 02, 2024
Tracked Since
Feb 18, 2026