7.5

CVE-2025-31387

WordPress InstaWP Connect plugin <= 0.1.0.82 - Local File Inclusion vulnerability

InstaWP Connect <= 0.1.0.82 - Unauthenticated Local File Inclusion

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This issue affects InstaWP Connect: from n/a through <= 0.1.0.82.
Mögliche Gegenmaßnahme
InstaWP Connect – 1-click WP Staging & Migration: Update to version 0.1.0.83, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerInstaWP
Produkt InstaWP Connect
Default Statusunaffected
Version <= 0.1.0.82
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt InstaWP Connect – 1-click WP Staging & Migration
Version *-0.1.0.82
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
audit@patchstack.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

https://patchstack.com/database/Wordpress/Plugin/instawp-connect/vulnerability/wordpress-instawp-connect-plugin-0-1-0-82-local-file-inclusion-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/c0e9726f-45cc-4759-909d-3de2ae9b2334
Third Party Advisory