Showing 1 vulnerability on this page for html2wp

Signals CISA KEV Ransomware Nuclei
html2wp_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

CWE-352CWE-434CWE-862Jun 27, 20221 related artifact
CVSS9.8v3.1EPSS11.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX