CVE-2026-73401: WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
Affected Software
1 affected component
WordPress InstaWP Connect plugin<=0.1.3.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress InstaWP Connect pluginto a version that resolves this vulnerability.Fixed in 0.1.3.8
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73401?
The severity of CVE-2026-73401 is medium with a score of 5.3.
2
How do I fix CVE-2026-73401?
To fix CVE-2026-73401, update the InstaWP Connect plugin to the latest version that addresses the Broken Access Control vulnerability.
3
What type of vulnerability is CVE-2026-73401?
CVE-2026-73401 is classified as an unauthenticated Broken Access Control vulnerability.
4
Who is affected by CVE-2026-73401?
All users running the InstaWP Connect plugin version 0.1.3.7 or earlier are affected by CVE-2026-73401.
5
When was CVE-2026-73401 published?
CVE-2026-73401 was published on August 13, 2026.