WP2HTML

WP2HTML has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for WP2HTML has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nabil Irawan. WP2HTML is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP2HTML vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2025-5930

WP2HTML <= 1.0.2 - Cross-Site Request Forgery to Settings Update

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
WP2HTML banner
Latestv1.0.3
0.0(0)
0/100
Last Updated
2025-08-04 (1y ago)
Active Installs
30+
Downloads
3,051
Requires WP
6.0+
Requires PHP
8.0+
Tested up to
WP 6.8.8
Created
2021-06-11 (5y ago)

Do you want to get rid of WordPress overheads? Let’s output static HTML and get rid of that overhead. If you use “?” in the permalink, adjust it that use slash-separated. You can select the pages you wish to output in the options screen. Outputs static HTML to the level below the folder where WordPress is installed. https://github.com/digital-acorn-jp/wp2html Usage Click the WP2HTML link in the sidebar, go to the plugins page. Set the options and the pages not generated, the pages to add. Click the Save button. Then you will see a list of paths in bottom of page. Check the paths. Click the Genarate button. Genarated the static HTMLs.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C