{"cve":"CVE-2022-1574","epss":{"score":0.12194},"mitre":{"cpes":[],"created":"2022-06-27T08:57:00+00:00","description":"The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2022/1xxx/CVE-2022-1574.json","references":["https://wpscan.com/vulnerability/c36d0ea8-bf5c-4af9-bd3d-911eb02adc14"],"title":"HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload","updated":"2024-08-03T00:10:03.721000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:html2wp_project:html2wp:*:*:*:*:*:wordpress:*:*"],"created":"2022-06-27T09:15:09.227000+00:00","description":"The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2022/CVE-2022-1574.json","references":["https://wpscan.com/vulnerability/c36d0ea8-bf5c-4af9-bd3d-911eb02adc14"],"title":null,"updated":"2026-06-17T04:22:41.920000+00:00","vendors":["html2wp_project","html2wp_project$PRODUCT$html2wp"],"weaknesses":["CWE-352","CWE-862"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:a:html2wp_project:html2wp:*:*:*:*:*:wordpress:*:*"],"providers":["nvd"]},"created":{"data":"2022-06-27T08:57:00+00:00","provider":"mitre"},"description":{"data":"The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.12194},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://wpscan.com/vulnerability/c36d0ea8-bf5c-4af9-bd3d-911eb02adc14"],"providers":["mitre","nvd"]},"title":{"data":"HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload","provider":"mitre"},"updated":{"data":"2024-11-21T06:40:59.883000+00:00","provider":"nvd"},"vendors":{"data":["html2wp_project","html2wp_project$PRODUCT$html2wp"],"providers":["nvd"]},"weaknesses":{"data":["CWE-352","CWE-862"],"providers":["nvd"]}}}