Themefic Instantio WordPress Plugin Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information in the Themefic Instantio WordPress plugin, affecting versions through 3.3.30. This issue allows unauthorized users to retrieve embedded sensitive data, which could be exploited to access other weaknesses in the system.

Impact

Exploitation of this vulnerability could lead to unauthorized viewing of sensitive information, typically restricted from regular users. Such data exposure could be used to exploit additional vulnerabilities within the system.

Remediation

Users of the WordPress Instantio plugin should update to version 3.3.31 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Apr 8, 2026, 11:13 AM
Updated: Apr 8, 2026, 11:13 AM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
2.5
exploitability
7.6
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.