Description
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:10:03.721Z
Reserved: 2022-05-04T00:00:00.000Z
Link: CVE-2022-1574
No data.
Status : Modified
Published: 2022-06-27T09:15:09.227
Modified: 2024-11-21T06:40:59.883
Link: CVE-2022-1574
No data.
OpenCVE Enrichment
No data.