Логотип exploitDog
bind:CVE-2022-1572
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1572

Количество 2

Количество 2

nvd логотип

CVE-2022-1572

больше 3 лет назад

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-c938-72w7-26mv

больше 3 лет назад

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1572

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c938-72w7-26mv

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу