S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1574 Scanner

CVE-2022-1574 scanner - Cross-Site Request Forgery (CSRF) vulnerability in HTML2WP plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1574
9.8
CVSS

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
HTML2WP
0
Updated Aug 22, 2026View on NVD →
Detail

The HTML2WP plugin for WordPress is designed to facilitate easy website transfers by simplifying the process of converting HTML files to WordPress themes. This process would typically be time-consuming and difficult, but the plugin automates the process, allowing users to more efficiently bring their website over to WordPress. The plugin does not require any technical skills to operate, making it very popular among WordPress users.

Recently, a severe vulnerability, designated as CVE-2022-1574, was discovered in the HTML2WP WordPress plugin. The vulnerability stems from the lack of authorization and CSRF checks when uploading files. This oversight means that attackers can upload potentially harmful files, such as PHP files, and execute arbitrary code on the remote server. The vulnerability is a serious one, and websites using the plugin are at high risk of exploitation.

When exploited, this vulnerability can lead to severe consequences for websites and web-based businesses. Attackers may gain access to sensitive information, such as user data or financial information. In addition, they can potentially cripple the website by executing code that can delete files or bring down the entire site. This vulnerability is particularly insidious because it can be exploited remotely by unauthenticated attackers.

Thanks to the pro features of the s4e.io platform, those who read this article can quickly and easily learn about vulnerabilities in their digital assets. The platform offers a comprehensive security analysis of all digital assets, enabling users to identify and mitigate security risks. By using the platform, users can ensure the security of their online assets and protect against potentially devastating attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following steps can be taken:

  • Update the HTML2WP plugin to the latest version as soon as it becomes available.
  • Implement additional checks for file uploads, such as authorisation checks and filetype validation.
  • Restrict file permissions to only allow the webserver to read files rather than write or execute them.
  • Implement a Web Application Firewall (WAF) that can detect and block attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.