Vulnerabilities (CVE)

Filtered by vendor Html2wp Project Subscribe
Filtered by product Html2wp
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1572 1 Html2wp Project 1 Html2wp 2022-07-07 5.5 MEDIUM 8.1 HIGH
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file