Impact
Unauthenticated access to privileged functions is possible in WordPress InstaWP Connect plugin versions 0.1.3.7 and lower. The flaw allows an attacker to execute actions that should be limited to users with appropriate permissions, thereby compromising the integrity of the WordPress site.
Affected Systems
The vulnerable software is the InstaWP Connect WordPress plugin with any version up to and including 0.1.3.7. The plugin is used within WordPress installations and provides integration services for the InstaWP platform.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level. No EPSS score is available, and the vulnerability is not listed in the KEV catalog. Based on the description, the likely attack vector involves unauthenticated HTTP requests to the plugin’s endpoints, allowing an attacker to bypass normal access controls. The attacker requires no special credentials or access capabilities to exploit the flaw.
OpenCVE Enrichment