📦 Instawp Connect

by Instawp

🔍 What is Instawp Connect?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-6397

CRITICAL CVSS 9.8 Jul 11, 2024

The InstaWP Connect WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, including administrators, if they know the usernam...

CVE-2024-37228

CRITICAL CVSS 10.0 Jun 24, 2024

This critical vulnerability in the InstaWP Connect WordPress plugin allows attackers to upload arbitrary files and execute malicious code on affected websites. It affects all WordPress sites running I...

CVE-2024-4898

CRITICAL CVSS 9.8 Jun 12, 2024

This vulnerability allows unauthenticated attackers to modify arbitrary WordPress site options and create administrator accounts via the InstaWP Connect plugin's REST API. It affects all WordPress sit...

CVE-2024-2667

CRITICAL CVSS 9.8 May 2, 2024

The InstaWP Connect WordPress plugin has an unauthenticated arbitrary file upload vulnerability in its REST API endpoint. This allows attackers to upload malicious files to vulnerable WordPress sites....

CVE-2024-25918

CRITICAL CVSS 9.9 Apr 3, 2024

This vulnerability allows attackers to upload malicious files to WordPress sites running the InstaWP Connect plugin, leading to remote code execution. It affects all WordPress installations using vuln...

CVE-2023-3956

CRITICAL CVSS 9.8 Jul 27, 2023

The InstaWP Connect WordPress plugin has a critical vulnerability that allows unauthenticated attackers to perform administrative actions without proper authorization. This includes adding/modifying/d...

CVE-2024-22145

HIGH CVSS 8.8 May 17, 2024

This vulnerability in the InstaWP Connect WordPress plugin allows attackers to update arbitrary WordPress options, leading to privilege escalation. Attackers can gain administrative access to WordPres...

CVE-2024-23506

HIGH CVSS 7.7 Jan 27, 2024

The InstaWP Connect WordPress plugin versions up to 0.1.0.9 contain a sensitive data exposure vulnerability that allows unauthorized actors to access confidential information. This affects WordPress s...

CVE-2024-32701

MEDIUM CVSS 4.3 Jun 9, 2024

This CVE describes a missing authorization vulnerability in the InstaWP Connect WordPress plugin. It allows unauthorized users to access functionality intended only for authorized administrators. All ...