CVE-2024-37228

Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
Configurations

Configuration 1 (hide)

cpe:2.3:a:instawp:instawp_connect:*:*:*:*:*:wordpress:*:*

History

23 Apr 2026, 15:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0

01 Apr 2026, 16:17

Type Values Removed Values Added
References
  • () https://patchstack.com/database/Wordpress/Plugin/instawp-connect/vulnerability/wordpress-instawp-connect-plugin-0-1-0-38-arbitrary-file-upload-vulnerability?_s_id=cve -
Summary (en) Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP Team InstaWP Connect allows Code Injection.This issue affects InstaWP Connect: from n/a through 0.1.0.38. (en) Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.
CWE CWE-94 CWE-434
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8

06 Feb 2025, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:instawp:instawp_connect:*:*:*:*:*:wordpress:*:*
First Time Instawp instawp Connect
Instawp
References () https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-38-arbitrary-file-upload-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-38-arbitrary-file-upload-vulnerability?_s_id=cve - Third Party Advisory

21 Nov 2024, 09:23

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de control inadecuado de la generación de código ("inyección de código") en InstaWP Team InstaWP Connect permite la inyección de código. Este problema afecta a InstaWP Connect: desde n/a hasta 0.1.0.38.
References () https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-38-arbitrary-file-upload-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-38-arbitrary-file-upload-vulnerability?_s_id=cve -

24 Jun 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 13:15

Updated : 2026-04-23 15:18


NVD link : CVE-2024-37228

Mitre link : CVE-2024-37228

CVE.ORG link : CVE-2024-37228


JSON object : View

Products Affected

instawp

  • instawp_connect
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type