Html2wp Project maintains a specialized WordPress content-conversion utility that translates HTML content into WordPress-compatible formats, with its vulnerability exposure centered on the html2wp plugin. The observed weakness classes—cross-site request forgery and missing authorization controls—reflect the plugin's web-facing integration points and its interaction with WordPress administrative functions, reflecting common risks in content-handling and privilege-boundary management within WordPress extensions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Html2wp Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1574CRITICAL The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can | Jun 27, 2022 | 9.8 | 48 | NO | YES |
CVE-2022-1572HIGH The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow | Jun 27, 2022 | 8.1 | 22 | NO | NO |
CVE-2022-1573MEDIUM The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them | Jun 27, 2022 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Html2wp Project.
Media articles that mention a CVE ID that affects a product developed by Html2wp Project — matched by CVE ID, not by vendor name.