Themefic Instantio WordPress Plugin Missing Authorization Vulnerability Allowing Settings Changes

Vulnerability

A missing authorization vulnerability exists in the Themefic Instantio WordPress plugin, affecting versions through 3.3.7. This vulnerability allows unauthorized users to exploit improperly configured access control settings, potentially leading to unauthorized changes in plugin settings.

Impact

Exploitation of this vulnerability could result in unauthorized changes to the plugin's settings, potentially disrupting the website's functionality or configuration.

Remediation

Users of the Themefic Instantio WordPress plugin should update to version 3.3.8 or later to address this vulnerability. Patchstack users can enable auto-updates for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.