PT-2024-33309 · WordPress · Instawp Connect
Truoc Phan
·
Published
2024-06-12
·
Updated
2024-07-23
·
CVE-2024-4898
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress versions up to, and including, 0.1.0.38
Description
The issue is related to missing authorization checks on the REST API calls, allowing unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options, and create administrator accounts.
Recommendations
For versions up to, and including, 0.1.0.38, update to a version that includes the necessary authorization checks for REST API calls to prevent arbitrary option updates.
As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Instawp Connect