Extension WordPress
Vulnérabilités InstaWP Connect – 1-click WP Staging & Migration
Cette page rassemble les failles publiées pour InstaWP Connect – 1-click WP Staging & Migration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de InstaWP Connect – 1-click WP Staging & Migration
16 fiches
InstaWP Connect <= 0.1.2.5 – Missing Authorization
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 0.1.2.5. This makes it possible for authenticated attackers, with subscriber-level access and…
*-0.1.2.5
0.1.2.7
11/03/2026
InstaWP Connect <= 0.1.1.9 – Missing Authorization
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 0.1.1.9. This makes it possible…
*-0.1.1.9
0.1.2.0
12/12/2025
InstaWP Connect <= 0.1.0.85 – Unauthenticated Local PHP File Inclusion
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to…
*-0.1.0.85
0.1.0.86
10/04/2025
InstaWP Connect <= 0.1.0.82 – Unauthenticated Local File Inclusion
The InstaWP Connect plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.0.82. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-0.1.0.82
0.1.0.83
29/03/2025
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.83 – Cross-Site Request Forgery to Local File Inclusion
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or incorrect nonce validation in the '/migrate/templates/main.php'…
*-0.1.0.83
0.1.0.84
13/03/2025
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.44 – Authentication Bypass to Admin
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it…
*-0.1.0.44
0.1.0.45
10/07/2024
InstaWP Connect <= 0.1.0.38 – Unauthenticated Arbitrary File Upload
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated…
*-0.1.0.38
0.1.0.39
21/06/2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 – Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This…
*-0.1.0.38
0.1.0.39
11/06/2024
InstaWP Connect <= 0.1.0.24 – Missing Authorization
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 0.1.0.24. This makes it possible for authenticated attackers, with subscriber-level access and…
*-0.1.0.24
0.1.0.25
22/04/2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 – Unauthenticated Arbitrary File Upload
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This…
*-0.1.0.22
0.1.0.23
12/04/2024
InstaWP Connect <= 0.1.0.8 – Authenticated (Subscriber+) Remote Code Execution
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-0.1.0.8
0.1.0.9
14/02/2024
InstaWP Connect <= 0.1.0.9 – Missing Authorization to Sensitive Information Dislcosure
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 0.1.0.9. This makes it possible for…
*-0.1.0.9
0.1.0.10
24/01/2024
InstaWP Connect <= 0.1.0.9 – Authenticated (Subscriber+) SQL Injection
The InstaWP Connect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-0.1.0.9
0.1.0.10
24/01/2024
InstaWP Connect <= 0.1.0.8 – Missing Authorization to Arbitrary Options Update
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_management_settings function in all versions up to, and including, 0.1.0.8. This…
*-0.1.0.8
0.1.0.9
17/01/2024
InstaWP Connect <= 0.1.0.8 – Cross-Site Request Forgery via create_file_db_manager
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.8. This is due to missing or incorrect nonce validation on the create_file_db_manager()…
*-0.1.0.8
0.1.0.9
12/01/2024
InstaWP Connect <= 0.0.9.18 – Missing Authorization to Unauthenticated Post/Taxonomy/User Add/Change/Delete, Customizer Setting Change, Plugin Installation/Activation/Deactication via events_receiver
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This…
*-0.0.9.18
0.0.9.19
26/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.