WordPress Plugin Vulnerabilities
HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
Description
The plugin does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Daniel Ruf
Submitter
Daniel Ruf
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-06-02 (about 3 years ago)
Added
2022-06-02 (about 3 years ago)
Last Updated
2023-03-04 (about 2 years ago)