Vulnerabilities > Html2Wp Project > Html2Wp > High

DATE CVE VULNERABILITY TITLE RISK
2022-06-27 CVE-2022-1572 Missing Authorization vulnerability in Html2Wp Project Html2Wp
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
network
low complexity
html2wp-project CWE-862
8.1