{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/instawp/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13457"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["InstaWP Connect (0.1.3.6)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","rce","apache"],"_cs_type":"advisory","_cs_vendors":["InstaWP"],"content_html":"\u003cp\u003eThe InstaWP Connect plugin for WordPress, in versions up to and including 0.1.3.6, contains a critical security flaw allowing unauthenticated remote code execution. The vulnerability stems from the plugin's practice of saving migration configuration data as 'options-{migrate_key}.txt' files within the 'wp-content/instawpbackups/' directory. Crucially, the plugin fails to include 'index.php' or '.htaccess' files to prevent directory indexing. On web servers configured with 'Options +Indexes', attackers can list the contents of this directory to retrieve the 40-character 'migrate_key'.\u003c/p\u003e\n\u003cp\u003eBy obtaining this key, an attacker can derive the AES-256-CBC decryption passphrase through a predictable SHA256 transformation. This allows for the decryption of the 'options' file, revealing the API signature and database credentials. While exploitation is time-limited to the active migration window, the resulting exposure enables full database compromise and subsequent remote code execution on the underlying server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site utilizing the InstaWP Connect plugin.\u003c/li\u003e\n\u003cli\u003eAttacker probes for directory indexing on the server by navigating to 'wp-content/instawpbackups/'.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves a listed 'options-{migrate_key}.txt' file from the directory index.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the 40-character 'migrate_key' string from the file name.\u003c/li\u003e\n\u003cli\u003eAttacker computes the AES-256-CBC passphrase using the derived SHA256 hash of the 'migrate_key'.\u003c/li\u003e\n\u003cli\u003eAttacker decrypts the options file to obtain the 'api_signature' and database credentials.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen API signature and database access to inject malicious code or commands into the WordPress database.\u003c/li\u003e\n\u003cli\u003eAttacker executes the injected code to gain full system control (Remote Code Execution).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to steal database credentials and the API signature, leading to unauthorized database manipulation, persistent backdoors, and full remote code execution on the WordPress instance. This vulnerability affects any environment where the plugin is active and the web server's 'Options +Indexes' configuration is enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internet-facing web server configurations to disable directory indexing ('Options -Indexes' in Apache).\u003c/li\u003e\n\u003cli\u003eDeploy web server log monitoring to detect requests targeting the '/wp-content/instawpbackups/' directory path.\u003c/li\u003e\n\u003cli\u003eUpdate the InstaWP Connect plugin to the latest secure version immediately.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on the 'wp-content/instawpbackups/' path to alert on unauthorized file enumeration or access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T21:50:56Z","date_published":"2026-08-11T21:50:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-instawp-rce/","summary":"The InstaWP Connect WordPress plugin (\u003c= 0.1.3.6) is vulnerable to remote code execution due to insecure configuration file storage and missing access controls on Apache servers with directory listing enabled.","title":"CVE-2026-13457: Remote Code Execution in InstaWP Connect Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-instawp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - InstaWP","version":"https://jsonfeed.org/version/1.1"}