Missing Authorization Vulnerability in InstaWP Connect by InstaWP
CVE-2025-66068

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2025

What is CVE-2025-66068?

A missing authorization vulnerability in InstaWP Connect allows attackers to exploit incorrectly configured access control security levels. This misconfiguration can lead to unauthorized access and manipulation of sensitive data. Affected versions of InstaWP Connect are up to and including 0.1.1.9, making it essential for users to apply necessary security measures to protect their installations.

Affected Version(s)

InstaWP Connect <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.
CVE-2025-66068 : Missing Authorization Vulnerability in InstaWP Connect by InstaWP