PatchSiren

InstaWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM InstaWP CVE published 2026-04-08

CVE-2026-39504

A Missing Authorization vulnerability was discovered in InstaWP Connect, affecting versions from n/a through 0.1.2.5. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.4 and a severity of MEDIUM. The vulnerability has a significant impact on access control, potentially allowing unauthorized actions. Users should review their configurations and u [truncated]