html2wp_project Vulnerabilities and Affected Products
Vulnerabilities associated with html2wp.
Products
Clear product- html2wp1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-1574CRITICAL | HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File UploadThe HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server | CVSS9.8v3.1 | EPSS11.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |