PT-2022-13971 · WordPress · Html2Wp

·

CVE-2022-1572

·

Published

2022-06-27

·

Updated

2023-07-04

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions HTML2WP WordPress plugin version 1.0.0
Description The issue is related to the lack of authorisation and CSRF checks in an AJAX action within the HTML2WP WordPress plugin. This could allow any authenticated user, including those with a subscriber role, to delete arbitrary files.
Recommendations For version 1.0.0, consider disabling the AJAX action until a patch is available to prevent potential exploitation. Restrict access to the plugin's functionality for lower-privileged users such as subscribers to minimize the risk of arbitrary file deletion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1572

Affected Products

Html2Wp