WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in InstaWP Connect – 1-click WP Staging & Migration

Create a staging WordPress site from production (live site). Ideal for testing updates, version change or re-write. Sync back only the changes.

18Reported vulnerabilities
10Highest CVSS score
0.1.3.8Latest version
40,000+Active installs

What to do now

Update InstaWP Connect – 1-click WP Staging & Migration to 0.1.3.8 or later. 18 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 12, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-2636 High 8.1 10.2% 0 to 0.1.0.85 (inclusive) 0.1.0.86 April 11, 2025
CVE-2024-2667 Critical 9.8 5.8% Before 0.1.0.23 0.1.0.23 May 2, 2024
CVE-2024-4898 Critical 9.8 4.2% Before 0.1.0.39 0.1.0.39 June 12, 2024
CVE-2024-37228 Critical 10 0.5% 0.1.0.38 and earlier 0.1.0.39 June 21, 2024
CVE-2023-3956 Critical 9.8 1.0% 0.0.9.18 and earlier 0.0.9.19 July 27, 2023
CVE-2025-31387 Critical 9.8 0.5% 0.1.0.82 and earlier 0.1.0.83 March 29, 2025
CVE-2024-6397 Critical 9.8 0.7% Before 0.1.0.45 0.1.0.45 July 11, 2024
CVE-2024-13913 High 8.8 2.6% 0 to 0.1.0.83 (inclusive) 0.1.0.84 March 14, 2025
CVE-2024-22145 High 8.8 1.1% 0.1.0.8 and earlier 0.1.0.9 January 17, 2024
CVE-2024-25918 High 8.8 0.7% 0.1.0.8 and earlier 0.1.0.9 February 14, 2024
CVE-2024-23507 High 8.8 0.6% 0.1.0.9 and earlier 0.1.0.10 January 24, 2024
CVE-2026-13457 High 7.5 0.6% 0 to 0.1.3.6 (inclusive) 0.1.3.7 August 11, 2026
CVE-2026-73401 Medium 5.3 0.2% 0.1.3.7 and earlier 0.1.3.8 August 13, 2026
CVE-2025-66068 Medium 5.3 0.2% 0.1.1.9 and earlier 0.1.2.0 December 12, 2025
CVE-2024-23506 Medium 4.3 0.5% 0.1.0.9 and earlier 0.1.0.10 January 24, 2024
CVE-2026-39504 Medium 4.3 0.2% 0.1.2.5 and earlier 0.1.2.7 March 11, 2026
CVE-2024-32701 Medium 4.3 0.3% 0.1.0.24 and earlier 0.1.0.25 April 22, 2024
WF-5954c35a-7d0a-4bc5-9cad-3223e7be56eb Medium 4.3 0.1.0.8 and earlier 0.1.0.9 January 12, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.