First published: Fri Jan 26 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in InstaWP Team InstaWP Connect – 1-click WP Staging & Migration.This issue affects InstaWP Connect – 1-click WP Staging & Migration: from n/a through 0.1.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
InstaWP Connect | <=0.1.0.9 |
Update to 0.1.0.10 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23506 is classified as moderate.
To fix CVE-2024-23506, update InstaWP Connect to the latest version beyond 0.1.0.9.
CVE-2024-23506 can expose sensitive configuration data and user information to unauthorized actors.
CVE-2024-23506 affects InstaWP Connect versions up to and including 0.1.0.9.
Users of the InstaWP Connect plugin for WordPress who are using affected versions are impacted by CVE-2024-23506.