Vulnerabilities (CVE)

Filtered by vendor Html2wp Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1574 1 Html2wp Project 1 Html2wp 2022-07-07 7.5 HIGH 9.8 CRITICAL
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server