Extension WordPress

Vulnérabilités InstaWP Connect – 1-click WP Staging & Migration

Cette page rassemble les failles publiées pour InstaWP Connect – 1-click WP Staging & Migration, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
6Critiques
16Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de InstaWP Connect – 1-click WP Staging & Migration

16 fiches

CVE-2025-2636 Élevée · 8,1
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.85 – Unauthenticated Local PHP File Inclusion

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to…

Versions affectées

*-0.1.0.85

Correctif

0.1.0.86

Publication

10/04/2025

CVE-2025-31387 Critique · 9,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.82 – Unauthenticated Local File Inclusion

The InstaWP Connect plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.0.82. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…

Versions affectées

*-0.1.0.82

Correctif

0.1.0.83

Publication

29/03/2025

CVE-2024-13913 Élevée · 8,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.83 – Cross-Site Request Forgery to Local File Inclusion

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.83. This is due to missing or incorrect nonce validation in the '/migrate/templates/main.php'…

Versions affectées

*-0.1.0.83

Correctif

0.1.0.84

Publication

13/03/2025

CVE-2024-6397 Critique · 9,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.44 – Authentication Bypass to Admin

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it…

Versions affectées

*-0.1.0.44

Correctif

0.1.0.45

Publication

10/07/2024

CVE-2024-4898 Critique · 9,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 – Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This…

Versions affectées

*-0.1.0.38

Correctif

0.1.0.39

Publication

11/06/2024

CVE-2024-32701 Moyenne · 4,3
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.24 – Missing Authorization

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 0.1.0.24. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

*-0.1.0.24

Correctif

0.1.0.25

Publication

22/04/2024

CVE-2024-2667 Critique · 9,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 – Unauthenticated Arbitrary File Upload

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This…

Versions affectées

*-0.1.0.22

Correctif

0.1.0.23

Publication

12/04/2024

CVE-2024-25918 Élevée · 8,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.8 – Authenticated (Subscriber+) Remote Code Execution

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-0.1.0.8

Correctif

0.1.0.9

Publication

14/02/2024

CVE-2024-23506 Moyenne · 4,3
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.9 – Missing Authorization to Sensitive Information Dislcosure

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 0.1.0.9. This makes it possible for…

Versions affectées

*-0.1.0.9

Correctif

0.1.0.10

Publication

24/01/2024

CVE-2024-22145 Élevée · 8,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.8 – Missing Authorization to Arbitrary Options Update

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_management_settings function in all versions up to, and including, 0.1.0.8. This…

Versions affectées

*-0.1.0.8

Correctif

0.1.0.9

Publication

17/01/2024

Vulnérabilité Moyenne · 4,3
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.1.0.8 – Cross-Site Request Forgery via create_file_db_manager

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.0.8. This is due to missing or incorrect nonce validation on the create_file_db_manager()…

Versions affectées

*-0.1.0.8

Correctif

0.1.0.9

Publication

12/01/2024

CVE-2023-3956 Critique · 9,8
InstaWP Connect – 1-click WP Staging & Migration

InstaWP Connect <= 0.0.9.18 – Missing Authorization to Unauthenticated Post/Taxonomy/User Add/Change/Delete, Customizer Setting Change, Plugin Installation/Activation/Deactication via events_receiver

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This…

Versions affectées

*-0.0.9.18

Correctif

0.0.9.19

Publication

26/07/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités