Record summary

CVE-2022-1574 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 18, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

HTML2WP

Default status: affected

CVE ListThrough 1.0.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress HTML2WP <=1.0.0 - Arbitrary File UploadCVSS 9.8

WordPress HTML2WP plugin through 1.0.0 contains an arbitrary file upload vulnerability. The plugin does not perform authorization and CSRF checks when importing files and does not validate them. As a result, an attacker can upload arbitrary files on the remote server.

Impact

An attacker can upload malicious files to the server, leading to remote code execution or unauthorized access.

Remediation

Update to the latest version of the plugin or remove it if not needed.

WeaknessesCWE-352
Authorstheamanrawat
Template tagscvecve2022wp-pluginwpfileuploadunauthwpscanwordpressintrusivehtml2wphtml2wp_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:html2wp_project:html2wp:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2