S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 26, 2025

CVE-2025-2636 Scanner

CVE-2025-2636 Scanner - Local File Inclusion (LFI) vulnerability in InstaWP Connect

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2636
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file types can be uploaded and included, or are already present on the filesystem locally. There are currently no known vulnerabilities in this plugin that make file upload possible, meaning this won't be exploitable to achieve remote code execution on most instances with just this plugin alone. Another vulnerability would need to be present on the site allowing arbitrary file upload in order to leverage this to achieve remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
InstaWP Connect – 1-click WP Staging & Migrationby instawp
0
Updated Aug 22, 2026View on NVD →
Detail

The InstaWP Connect plugin is designed to facilitate 1-click staging and migration of WordPress websites. It is used by web administrators and developers to efficiently replicate website environments for testing and migration purposes. The plugin’s core function is to simplify the deployment and management of WordPress sites, making it indispensable for many WordPress users. It is often employed in development environments to maintain seamless updates and experiment with site changes. By creating an identical staging site, users can test new features without affecting the live environment. This significantly mitigates risks associated with updates or new installations on WordPress platforms.

The identified vulnerability in InstaWP Connect is a Local File Inclusion (LFI) weakness. It allows unauthorized attackers to include and execute arbitrary files on the server. This could result in the execution of any PHP code contained within those files, posing significant security risks. Such vulnerabilities are critical as they could permit extensive unauthorized access and manipulation of server resources. LFI allows attackers to escalate from a minor misconfiguration to full server exploitation, potentially leading to data breaches. The vulnerability is particularly concerning due to the ease with which it can be exploited without authenticated access.

The technical specifics of the vulnerability involve exploiting the 'instawp-database-manager' parameter. Unauthorized users can manipulate this parameter to execute malicious PHP scripts by referencing system files outside of the plugin’s permitted directory. The vulnerability affects all versions up to and including 0.1.0.85. By manipulating the file parameters, attackers can induce the server to process arbitrary files. This significantly increases the risk of full-scale server compromise, particularly when sensitive configuration files are accessed or modified.

If exploited, this vulnerability could lead to several severe outcomes. An attacker could execute malicious code leading to complete server compromise. They could read sensitive configuration files, leading to information disclosure. Additionally, such exploitation could result in backend server functionality manipulation, impacting overall site integrity. In worse scenarios, it could provide a foothold for attackers to gain further access to an organization’s network, escalating to broader data breaches. Finally, sites using vulnerable versions might be susceptible to downtime or defacement, impacting business operation and reputation.

REFERENCES

Solution Advice
  • Update the InstaWP Connect plugin to version 0.1.0.86 or later immediately to patch the vulnerability.
  • Conduct thorough security audits and penetration testing to identify any further vulnerabilities in connected plugins.
  • Implement file permission and inclusion controls to prevent unauthorized file access or execution on servers.
  • Regularly monitor server logs for unusual activities that could indicate LFI attempts.
  • Educate and train staff on best practices regarding plugin updates and security protocols.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.