8.1

CVE-2022-1572

Exploit

HTML2WP <= 1.0.0 - Subscriber+ Arbitrary File Deletion

HTML2WP <= 1.0.0 - Arbitrary File Deletion

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
Mögliche Gegenmaßnahme
HTML2WP: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Html2wp ProjectHtml2wp SwPlatformwordpress Version <= 1.0.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt HTML2WP
Version *-1.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:N/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://wpscan.com/vulnerability/9afd1805-d449-4551-986a-f92cb47c95c5
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/72b4fe0f-13cd-4580-9010-1a3e66000251
Third Party Advisory