PT-2025-16025 · WordPress · Instawp Connect

Cheng Liu

·

Published

2025-04-11

·

Updated

2025-09-15

·

CVE-2025-2636

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress versions up to, and including, 0.1.0.85
Description: The InstaWP Connect plugin is vulnerable to Local File Inclusion via the instawp-database-manager parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, enabling the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Recommendations: For versions up to, and including, 0.1.0.85, update to version 0.1.0.86 or later to secure the website. As a temporary workaround, consider restricting access to the instawp-database-manager parameter to minimize the risk of exploitation.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-2636

Affected Products

Instawp Connect