Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Instawp ConnectAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |
| Aplazada | Alta (7.5) | 0.85% | — | Instawp ConnectAI | 11/8/2026 | 12/8/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. This is due to the plugin stores its encrypted options file as options-{migrate_key}.txt in wp-content/instawpbackups/… | |
| Aplazada | Media (5.4) | 0.23% | — | Instawp ConnectAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5. | |
| Aplazada | Media (6.5) | 0.23% | — | Instawp ConnectAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9. | |
| Aplazada | Alta (8.1) | 10% | — | Instawp ConnectAI | 11/4/2025 | 17/6/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server,… | |
| Aplazada | Alta (7.5) | 0.53% | — | Instawp ConnectAI | 31/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This issue affects InstaWP Connect: from n/a through <= 0.1.0.82. | |
| Aplazada | Alta (8.8) | 2.7% | — | Instawp ConnectAI | 14/3/2025 | 17/6/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or incorrect nonce validation in the '/migrate/templates/main.php' file. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.70% | — | Instawp Connect | 11/7/2024 | 17/6/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Modificada | Crítica (9.8) | 0.53% | — | Instawp Connect | 24/6/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38. | |
| Modificada | Crítica (9.8) | 4.2% | — | Instawp Connect | 12/6/2024 | 17/6/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit… | |
| Modificada | Alta (8.8) | 0.33% | — | Instawp Connect | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.24. | |
| Modificada | Alta (8.8) | 1.1% | — | Instawp Connect | 17/5/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | |
| Modificada | Crítica (9.8) | 5.8% | — | Instawp Connect | 2/5/2024 | 17/6/2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.8) | 0.68% | — | Instawp Connect | 3/4/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | |
| Modificada | Alta (8.8) | 0.62% | — | Instawp Connect | 31/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. | |
| Modificada | Media (6.5) | 0.50% | — | Instawp Connect | 27/1/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. | |
| Modificada | Crítica (9.8) | 0.97% | — | Instawp Connect | 27/7/2023 | 17/6/2026 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated attackers to add, modify or delete post… |