The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-27T08:56:52

Updated: 2024-08-03T00:10:03.642Z

Reserved: 2022-05-04T00:00:00

Link: CVE-2022-1572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-27T09:15:09.120

Modified: 2023-11-07T03:42:00.793

Link: CVE-2022-1572

cve-icon Redhat

No data.