Instawp develops WordPress management and hosting tools that sit in the authentication and deployment path of site administration, and its vulnerability profile skews strongly toward critical-severity outcomes. The exposure concentrates in products such as Instawp Connect and String Locator, recurs through authentication and access-control weaknesses including missing authorization, authentication bypass via alternate channels, and improper deserialization, and frequently acquires public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Instawp over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2667CRITICAL The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-conne | May 2, 2024 | 9.8 | 41 | NO | YES |
CVE-2024-4898CRITICAL The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in a | Jun 12, 2024 | 9.8 | 40 | NO | YES |
CVE-2024-6397CRITICAL The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insu | Jul 11, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-37228CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38. | Jun 24, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-22145HIGH Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | May 17, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-3956CRITICAL The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiv | Jul 27, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-10936HIGH The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_u | Jan 21, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-25918HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | Apr 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-32701HIGH Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.24. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-23507HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: fr | Jan 31, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Instawp.
Media articles that mention a CVE ID that affects a product developed by Instawp — matched by CVE ID, not by vendor name.