Product
The InstaWP Connect WordPress plugin (<= 0.1.3.6) is vulnerable to remote code execution due to insecure configuration file storage and missing access controls on Apache servers with directory listing enabled.