Junglewise Threat Intelligence

CVE-2026-39504: InstaWP InstaWP Connect missing authorization

CVE-2026-39504 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Executive brief

InstaWP Connect, a WordPress plugin used to connect sites to the InstaWP staging platform, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to perform actions or access information they should not be authorized to see. While the impact is considered moderate, it could lead to unauthorized changes or data exposure on the affected WordPress site.

Technical details

A missing authorization vulnerability (CWE-862) exists in the InstaWP Connect plugin for WordPress through version 0.1.2.5. The flaw stems from incorrectly configured access control security levels within the plugin's functional logic. A remote attacker with basic 'Subscriber' level authentication can exploit this to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is resolved in version 0.1.2.7.

Affected products

  • InstaWP InstaWP Connect <= 0.1.2.5

Timeline

  • 2026-02-09: other: Reported by researcher Nabil Irawan
  • 2026-03-11: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-03-11: patched: Patch released in version 0.1.2.7

References

Related threats