Remote Code Execution in InstaWP Connect Plugin for WordPress
CVE-2026-13457

7.5HIGH

What is CVE-2026-13457?

The InstaWP Connect plugin for WordPress is susceptible to a Remote Code Execution vulnerability. This is due to the insecure storage of its encrypted options file in the wp-content/instawpbackups/ directory, under an improperly configured environment. When the directory listing feature is enabled on Apache servers, attackers can access sensitive information, including the migrate_key. By exploiting this vulnerability during the migration period, unauthorized individuals can recover the AES-256-CBC passphrase, leading to potential unauthorized database access and the recovery of api_signature. Proper security measures should include disabling directory listing and ensuring proper file access controls are in place.

Affected Version(s)

InstaWP Connect – 1-click WP Staging & Migration 0 <= 0.1.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xsabre
.