CVE-2026-73401
- EPSS 0.21%
- Veröffentlicht 13.08.2026 13:37:25
- Zuletzt bearbeitet 14.08.2026 19:09:39
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
CVE-2026-13457
- EPSS 0.62%
- Veröffentlicht 11.08.2026 19:37:28
- Zuletzt bearbeitet 12.08.2026 21:00:52
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. This is due to the plugin stores its encrypted options...
CVE-2026-39504
- EPSS 0.17%
- Veröffentlicht 08.04.2026 08:30:13
- Zuletzt bearbeitet 24.07.2026 21:10:00
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5.
CVE-2025-66068
- EPSS 0.23%
- Veröffentlicht 18.12.2025 07:22:17
- Zuletzt bearbeitet 27.04.2026 18:16:32
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.
CVE-2025-2636
- EPSS 10.24%
- Veröffentlicht 11.04.2025 04:21:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated at...
CVE-2025-31387
- EPSS 0.5%
- Veröffentlicht 31.03.2025 06:15:30
- Zuletzt bearbeitet 23.04.2026 15:27:44
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This issue affects InstaWP Connect: from n/a through <= 0...
CVE-2024-13913
- EPSS 2.63%
- Veröffentlicht 14.03.2025 06:15:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or incorrect nonce validation in the '/migrate/templates/main...
CVE-2024-6397
- EPSS 0.71%
- Veröffentlicht 11.07.2024 04:15:05
- Zuletzt bearbeitet 08.04.2026 18:22:21
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unaut...
CVE-2024-37228
- EPSS 0.53%
- Veröffentlicht 24.06.2024 13:15:10
- Zuletzt bearbeitet 23.04.2026 15:18:33
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
CVE-2024-4898
- EPSS 4.16%
- Veröffentlicht 12.06.2024 11:15:50
- Zuletzt bearbeitet 08.04.2026 18:21:57
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for...