CVSS v3
9.8
CRITICAL
EPSS Score
73.7%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
Active exploitation of CVE-2022-1574 has not been confirmed. The EPSS score is 73.7%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2022-1574 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).