Fiche vulnérabilité
CVE-2022-1572 : faille élevée html2wp project html2wp (CVSS 8.1)
Description
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
En bref
- Sévérité
- Élevée (CVSS 8.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 27 juin 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- html2wp project html2wp