CVE-2024-22145: WordPress InstaWP Connect plugin <= 0.1.0.8 - Arbitrary Option Update to Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
Affected Software
3 affected components
InstaWP InstaWP Connect<=0.1.0.8
WordPress InstaWP Connect<=0.1.0.8
InstaWP Instawp Connect Wordpress<0.1.0.9
Remediation
Information
Update to 0.1.0.9 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22145?
CVE-2024-22145 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2024-22145?
To fix CVE-2024-22145, upgrade InstaWP Connect to version 0.1.0.9 or later.
3
Which software is affected by CVE-2024-22145?
CVE-2024-22145 affects InstaWP Connect versions up to and including 0.1.0.8.
4
What is the impact of CVE-2024-22145?
The impact of CVE-2024-22145 is that it allows attackers to escalate their privileges within the affected application.
5
Who should be concerned about CVE-2024-22145?
Website administrators using InstaWP Connect versions 0.1.0.8 or earlier should be concerned about CVE-2024-22145.