WordPress Plugin Vulnerabilities
InstaWP Connect < 0.0.9.19 - Unauthenticated Data Modification
Description
The plugin does not have authorisation check in its events_receiver function, allowing unauthenticated users to create/update/delete posts/taxonomy, install/activate/deactivate plugin, update the customizer settings as well as create/update/delete arbitrary users
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Lana Codes
Verified
No
WPVDB ID
Timeline
Publicly Published
2023-07-26 (about 2 years ago)
Added
2023-07-27 (about 2 years ago)
Last Updated
2023-07-27 (about 2 years ago)