CVE-2022-1574: HTML2WP Project HTML2WP
Critical severity, CVSS 9.8. EPSS: 12.2% chance of exploitation in the next 30 days.
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Affected products
- HTML2WP Project HTML2WP: up to and including 1.0.0
Published 2022-06-27. Last modified 2026-06-17.