HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 12%
from disclosure to weapon
Published on NVDJun 27
VulnCheck+1240d
exploitation probability
12%top 4% of all CVEs
observed exploitation
yesVulnCheck
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Affected products
Unknown · HTML2WP