This vulnerability follows previous security issues discovered in earlier versions of InstaWP Connect, including authentication bypass vulnerabilities in versions 0.1.0.44 and 0.1.0.38. It highlights the importance of maintaining up-to-date plugin installations. Security researchers at Wordfence identified and reported the critical flaw (CVE-2025-2636), which allows unauthenticated attackers to execute arbitrary code on affected websites. In scenarios where image uploads or other “safe” file types are permitted, attackers could upload malicious PHP code disguised as legitimate files and then use the LFI vulnerability to execute them. The vulnerability allows attackers to bypass access controls, obtain sensitive data, including database credentials, and achieve code execution. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Security researcher Cheng Liu discovered that the plugin fails to properly validate user input before passing it to PHP, including functions. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. Website administrators are urged to update immediately as the vulnerability received a CVSS score of 9.8, the highest severity rating possible.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 11 Apr 2025 12:10:16 +0000