Remote Code Execution in InstaWP Connect Plugin for WordPress
CVE-2026-13457
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-13457?
The InstaWP Connect plugin for WordPress is susceptible to a Remote Code Execution vulnerability. This is due to the insecure storage of its encrypted options file in the wp-content/instawpbackups/ directory, under an improperly configured environment. When the directory listing feature is enabled on Apache servers, attackers can access sensitive information, including the migrate_key. By exploiting this vulnerability during the migration period, unauthorized individuals can recover the AES-256-CBC passphrase, leading to potential unauthorized database access and the recovery of api_signature. Proper security measures should include disabling directory listing and ensuring proper file access controls are in place.
Affected Version(s)
InstaWP Connect β 1-click WP Staging & Migration 0 <= 0.1.3.6