Instawp
Instawp Connect: vulnerabilidades y CVE
Instawp Connect tiene 17 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses4
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73401 | Media (5.3) | 0.29% | — | 13 ago 2026 | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. |
| CVE-2026-13457 | Alta (7.5) | 0.85% | — | 11 ago 2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. This is due to the… |
| CVE-2026-39504 | Media (5.4) | 0.23% | — | 8 abr 2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5. |
| CVE-2025-66068 | Media (6.5) | 0.23% | — | 18 dic 2025 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9. |
| CVE-2025-2636 | Alta (8.1) | 10% | — | 11 abr 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it… |
| CVE-2025-31387 | Alta (7.5) | 0.53% | — | 31 mar 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This issue affects InstaWP… |
| CVE-2024-13913 | Alta (8.8) | 2.7% | — | 14 mar 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or incorrect nonce validation… |
| CVE-2024-6397 | Crítica (9.8) | 0.70% | — | 11 jul 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key.… |
| CVE-2024-37228 | Crítica (9.8) | 0.53% | — | 24 jun 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38. |
| CVE-2024-4898 | Crítica (9.8) | 4.2% | — | 12 jun 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including,… |
| CVE-2024-32701 | Alta (8.8) | 0.33% | — | 9 jun 2024 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.24. |
| CVE-2024-22145 | Alta (8.8) | 1.1% | — | 17 may 2024 | Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. |
| CVE-2024-2667 | Crítica (9.8) | 5.8% | — | 2 may 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all… |
| CVE-2024-25918 | Alta (8.8) | 0.68% | — | 3 abr 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. |
| CVE-2024-23507 | Alta (8.8) | 0.62% | — | 31 ene 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. |
| CVE-2024-23506 | Media (6.5) | 0.50% | — | 27 ene 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. |
| CVE-2023-3956 | Crítica (9.8) | 0.97% | — | 27 jul 2023 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.