Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

String Locator HIGH 8.8
CVE-2024-10936

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untr…

Fix: 2.6.7+
Fix from $1,950 2025-01-21
String Locator MEDIUM 6.1
CVE-2023-6987

The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter in all versions up to, and inc…

Fix: 2.6.6+
Fix from $1,600 2024-08-24
Instawp Connect CRITICAL 9.8
CVE-2024-6397

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including…

Fix: 0.1.0.45+
Fix from $2,300 2024-07-11
Instawp Connect CRITICAL 9.8
CVE-2024-37228

Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a…

Fix: 0.1.0.39+
Fix from $2,300 2024-06-24
Instawp Connect CRITICAL 9.8
CVE-2024-4898

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization ch…

Fix: 0.1.0.39+
Fix from $2,300 2024-06-12
Instawp Connect HIGH 8.8
CVE-2024-32701

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.24.

Fix: 0.1.0.25+
Fix from $1,950 2024-06-09
Instawp Connect HIGH 8.8
CVE-2024-22145

Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0…

Fix: 0.1.0.9+
Fix from $1,950 2024-05-17
Instawp Connect CRITICAL 9.8
CVE-2024-2667EPSS 6%

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio…

Fix: 0.1.0.23+
Fix from $2,300 2024-05-02
Instawp Connect HIGH 8.8
CVE-2024-25918

Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect…

Fix: 0.1.0.9+
Fix from $1,950 2024-04-03
Instawp Connect HIGH 8.8
CVE-2024-23507

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This is…

Fix: after 0.1.0.9
Fix from $1,950 2024-01-31
Instawp Connect MEDIUM 6.5
CVE-2024-23506

Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n…

Fix: after 0.1.0.9
Fix from $1,600 2024-01-27
Instawp Connect CRITICAL 9.8
CVE-2023-3956

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capabil…

Fix: after 0.0.9.18
Fix from $2,300 2023-07-27
String Locator HIGH 8.8
CVE-2022-2434

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to…

Fix: after 2.5.0
Fix from $1,950 2022-09-06