Vulnerabilities > CVE-2022-1574 - Missing Authorization vulnerability in Html2Wp Project Html2Wp

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
html2wp-project
CWE-862
critical

Summary

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

Vulnerable Configurations

Part Description Count
Application
Html2Wp_Project
1

Common Weakness Enumeration (CWE)