CVE-2024-2667

CRITICAL EXPLOITED NUCLEI

InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload

Title source: nuclei

Description

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

Exploits (3)

nomisec WORKING POC 2 stars
by Puvipavan · remote
https://github.com/Puvipavan/CVE-2024-2667
nomisec WORKING POC
by Nxploited · remote
https://github.com/Nxploited/CVE-2024-2667-Poc
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-2667-Poc

Nuclei Templates (1)

InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
CRITICALVERIFIEDby DhiyaneshDK
FOFA: body="/wp-content/plugins/instawp-connect/"

Scores

CVSS v3 9.8
EPSS 0.9014
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2024-04-12

Classification

CWE
CWE-434
Status published

Affected Products (1)

instawp/instawp_connect < 0.1.0.23

Timeline

Published May 02, 2024
Tracked Since Feb 18, 2026