Vulnerability Description
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Html2Wp Project | Html2Wp | <= 1.0.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9afd1805-d449-4551-986a-f92cb47c95c5ExploitThird Party Advisory
- https://wpscan.com/vulnerability/9afd1805-d449-4551-986a-f92cb47c95c5ExploitThird Party Advisory
FAQ
What is CVE-2022-1572?
CVE-2022-1572 is a vulnerability with a CVSS score of 8.1 (HIGH). The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbi...
How severe is CVE-2022-1572?
CVE-2022-1572 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1572?
Check the references section above for vendor advisories and patch information. Affected products include: Html2Wp Project Html2Wp.