Vulnerabilities > CVE-2022-1572 - Missing Authorization vulnerability in Html2Wp Project Html2Wp

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
html2wp-project
CWE-862

Summary

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

Vulnerable Configurations

Part Description Count
Application
Html2Wp_Project
1

Common Weakness Enumeration (CWE)