ZeroHour

CVE-2022-1572

PoC
CVSS 3.1
8.1 high
EPSS
<1%p44
Published
()
Modified
Description

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

Vendors
html2wp project
Products
html2wp
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.