plugin

Instantio Vulnerabilities

4 known security issues reported for the Instantio WordPress plugin. Most recent disclosed Mar 25, 2026.

2 high 2 medium

Running Instantio on your site? Check whether your installed version is affected.

Scan your site free

Instantio <= 3.3.30 - Unauthenticated Information Exposure

medium

The Instantio — Side Cart & One-Page Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.3.30
Fixed in:
3.3.31
Disclosed:
Mar 25, 2026

CVE-2026-39571 on NVD →

Instantio <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload

high

The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.16. This makes it possible for authenticated attackers, with Administrator-level...

CVSS:
7.2
Affected:
up to 3.3.16
Fixed in:
3.3.17
Disclosed:
May 7, 2025

CVE-2025-47550 on NVD →

Instantio <= 3.3.7 - Missing Authorization to Unauthenticated Settings Update

medium

The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.7. This makes it possible for unauthenticated attackers to update plugin...

CVSS:
5.3
Affected:
up to 3.3.7
Fixed in:
3.3.8
Disclosed:
Dec 18, 2024

CVE-2025-24581 on NVD →

Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart <= 1.2.5 - Cross Site Request Forgery

high

The Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the instantio_lite_ajax_quickview_variable_products function. This makes...

CVSS:
8.8
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jun 30, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database