WordPress HTML2WP plugin through 1.0.0 contains an arbitrary file upload vulnerability. The plugin does not perform authorization and CSRF checks when importing files and does not validate them. As a result, an attacker can upload arbitrary files on the remote server.
View the template here CVE-2022-1574.yaml
References:
https://wordpress.org/plugins/html2wp/