Instantio <= 3.3.30 - Unauthenticated Information Exposure
medium
The Instantio — Side Cart & One-Page Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.3.30
- Fixed in:
- 3.3.31
- Disclosed:
- Mar 25, 2026
CVE-2026-39571 on NVD →
Instantio <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload
high
The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.16. This makes it possible for authenticated attackers, with Administrator-level...
- CVSS:
- 7.2
- Affected:
- up to 3.3.16
- Fixed in:
- 3.3.17
- Disclosed:
- May 7, 2025
CVE-2025-47550 on NVD →
Instantio <= 3.3.7 - Missing Authorization to Unauthenticated Settings Update
medium
The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.7. This makes it possible for unauthenticated attackers to update plugin...
- CVSS:
- 5.3
- Affected:
- up to 3.3.7
- Fixed in:
- 3.3.8
- Disclosed:
- Dec 18, 2024
CVE-2025-24581 on NVD →
Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart <= 1.2.5 - Cross Site Request Forgery
high
The Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the instantio_lite_ajax_quickview_variable_products function. This makes...
- CVSS:
- 8.8
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Jun 30, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database