peter bassill · operator
$ cve CVE-2024-4898 JSON

CVE-2024-4898

9.8
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.16% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-862
On CISA KEVno
Public exploitnone known
Published2024-06-12
Last modified2026-06-17

Affected (1)

VendorProduct
instawpinstawp connect

References

→ the Explorer  ·  watch your stack  ·  NVD