CVE-2024-25918: WordPress InstaWP Connect plugin <= 0.1.0.8 - Remote Code Execution vulnerability
Published Apr 3, 2024
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
Affected Software
3 affected components
InstaWP Team InstaWP Connect<=0.1.0.8
WordPress InstaWP Connect<=0.1.0.8
InstaWP Instawp Connect Wordpress<0.1.0.9
Remediation
Information
Update to 0.1.0.9 or a higher version.
Event History
Apr 3, 2024
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25918?
CVE-2024-25918 is classified as a critical vulnerability due to its potential for code injection via dangerous file uploads.
2
How do I fix CVE-2024-25918?
To fix CVE-2024-25918, update your InstaWP Connect plugin to the latest version above 0.1.0.8.
3
What products are affected by CVE-2024-25918?
CVE-2024-25918 affects the InstaWP Connect plugin for WordPress up to version 0.1.0.8.
4
Can CVE-2024-25918 be exploited remotely?
Yes, CVE-2024-25918 can be exploited remotely, allowing attackers to perform code injection.
5
What types of attacks can CVE-2024-25918 lead to?
CVE-2024-25918 can lead to remote code execution attacks, compromising the security of the affected WordPress site.