CVE-2022-1574
HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2022-1574 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 18, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
HTML2WPDefault status: affected | CVE List | Through 1.0.0 | affected |
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryCRITICALWordPress HTML2WP <=1.0.0 - Arbitrary File UploadCVSS 9.8
WordPress HTML2WP plugin through 1.0.0 contains an arbitrary file upload vulnerability. The plugin does not perform authorization and CSRF checks when importing files and does not validate them. As a result, an attacker can upload arbitrary files on the remote server.
Impact
An attacker can upload malicious files to the server, leading to remote code execution or unauthorized access.
Remediation
Update to the latest version of the plugin or remove it if not needed.
Source: ProjectDiscovery