CVE-2024-2667: InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2667?
CVE-2024-2667 has a critical severity level due to the potential for arbitrary file uploads.
How do I fix CVE-2024-2667?
To mitigate CVE-2024-2667, update the InstaWP Connect plugin to version 0.1.0.23 or later.
What versions of InstaWP Connect are affected by CVE-2024-2667?
All versions of InstaWP Connect up to and including 0.1.0.22 are affected by CVE-2024-2667.
Can unauthenticated users exploit CVE-2024-2667?
Yes, CVE-2024-2667 allows unauthenticated users to exploit the vulnerability by uploading arbitrary files.
What is the method of exploitation for CVE-2024-2667?
CVE-2024-2667 can be exploited through insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint.