Description
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.
Published: 2025-12-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the InstaWP Connect plugin for WordPress, allowing attackers to bypass intended access controls and exploit incorrectly configured security levels. This weakness can lead to unauthorized creation, deletion, or modification of data exposed by the plugin, thereby compromising data integrity and potentially allowing further malicious activity. The flaw is listed as CWE-862, indicating improper access control.

Affected Systems

WordPress sites using the InstaWP Connect plugin are affected. All users of the plugin versions from the earliest available release up through 0.1.1.9 are vulnerable. The vendor, InstaWP, does not provide exact revision numbers beyond the maximum affected version. Sites with older or unpatched plugin installations should be evaluated to confirm they fall within this range.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity level, while the EPSS score of less than 1% shows a low probability of exploitation at this time and the vulnerability is not listed in CISA KEV. The likely attack vector is the web application; an attacker with basic access to the WordPress environment—whether authenticated at a low‑privilege role or possibly unauthenticated depending on site configuration—can exploit the missing authorization to perform privileged actions within the plugin. The exploit requires no special preconditions beyond access to the plugin’s exposed endpoints.

Generated by OpenCVE AI on April 29, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the InstaWP Connect plugin to a version newer than 0.1.1.9 as soon as the vendor releases an update.
  • Re‑evaluate WordPress user roles and ensure that only trusted editors or administrators have permissions that allow accessing the InstaWP Connect plugin.
  • Consider disabling the plugin if it is not required for site functionality until a secure version is available.

Generated by OpenCVE AI on April 29, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Instawp
Instawp instawp Connect
Wordpress
Wordpress wordpress
Vendors & Products Instawp
Instawp instawp Connect
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.
Title WordPress InstaWP Connect plugin <= 0.1.1.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Instawp Instawp Connect
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:15.712Z

Reserved: 2025-11-21T11:20:46.955Z

Link: CVE-2025-66068

cve-icon Vulnrichment

Updated: 2025-12-18T15:58:44.902Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:15.153

Modified: 2026-04-27T18:16:32.927

Link: CVE-2025-66068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses