Lucene search

K
wpvulndbWpvulndbWPVDB-ID:4BA053A1-D55B-452D-919B-A123C121F67A
HistoryJan 26, 2024 - 12:00 a.m.

InstaWP Connect < 0.1.0.10 - Missing Authorization to Sensitive Information Dislcosure

2024-01-2600:00:00
wpscan.com
9
instawp connect
wordpress
vulnerability
authorization
sensitive information

6.4 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.3%

Description The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 0.1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive information.

CPENameOperatorVersion
eq0.1.0.10

6.4 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.3%

Related for WPVDB-ID:4BA053A1-D55B-452D-919B-A123C121F67A