PT-2024-33309 · WordPress · Instawp Connect

Truoc Phan

·

Published

2024-06-12

·

Updated

2024-07-23

·

CVE-2024-4898

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress versions up to, and including, 0.1.0.38
Description The issue is related to missing authorization checks on the REST API calls, allowing unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options, and create administrator accounts.
Recommendations For versions up to, and including, 0.1.0.38, update to a version that includes the necessary authorization checks for REST API calls to prevent arbitrary option updates. As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-4898

Affected Products

Instawp Connect