What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
Explanation of Vulnerability in Simple Terms
InstaWP Connect versions up to 0.1.0.8 contain a code injection vulnerability that allows authenticated users to run arbitrary PHP code on the site. An attacker with low-level access can execute malicious code with full site privileges, potentially compromising the entire installation. The vulnerability affects the scope beyond the vulnerable component itself.
What an attacker can do
Run arbitrary PHP code on the site with full administrative privileges.
Potential impact on your site
Complete site compromise: data theft, malware injection, account takeover, or total loss of control.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities