Unauthenticated Broken Access Control in InstaWP Connect by InstaWP
CVE-2026-73401
5.3MEDIUM
What is CVE-2026-73401?
The InstaWP Connect plugin versions up to 0.1.3.7 are susceptible to an unauthenticated broken access control vulnerability. This flaw allows unauthorized users to access sensitive functionalities, potentially leading to unauthorized actions within the application. It is crucial for users to evaluate their usage of this plugin and consider updating to the latest version to mitigate related security risks.
Affected Version(s)
InstaWP Connect <= 0.1.3.7