Vulnerabilities > CVE-2022-1574 - Missing Authorization vulnerability in Html2Wp Project Html2Wp
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |