CVE-2024-23506: WordPress InstaWP Connect plugin <= 0.1.0.9 - Sensitive Data Exposure vulnerability
Published Jan 26, 2024
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9.
Affected Software
1 affected component
InstaWP Instawp Connect Wordpress<=0.1.0.9
Remediation
Information
Update to 0.1.0.10 or a higher version.
Event History
Jan 26, 2024
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness
Jan 27, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23506?
The severity of CVE-2024-23506 is classified as moderate.
2
How do I fix CVE-2024-23506?
To fix CVE-2024-23506, update InstaWP Connect to the latest version beyond 0.1.0.9.
3
What types of sensitive information are exposed in CVE-2024-23506?
CVE-2024-23506 can expose sensitive configuration data and user information to unauthorized actors.
4
Which versions of InstaWP Connect are affected by CVE-2024-23506?
CVE-2024-23506 affects InstaWP Connect versions up to and including 0.1.0.9.
5
Who is impacted by CVE-2024-23506?
Users of the InstaWP Connect plugin for WordPress who are using affected versions are impacted by CVE-2024-23506.