What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
Explanation of Vulnerability in Simple Terms
InstaWP Connect versions up to 0.1.0.38 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files over the network with no authentication or user interaction required. This can lead to remote code execution, data theft, and site takeover. Update to a version newer than 0.1.0.38 immediately.
What an attacker can do
Upload malicious files to the site and run their own code on it.
Potential impact on your site
Complete site compromise: attackers can execute code, steal data, and modify or delete content.
Conditions required to exploit
Network access only; no authentication or user interaction needed.
Key dates
External resources
Related vulnerabilities