WP2HTML
WP2HTML has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for WP2HTML has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. WP2HTML is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-5930WP2HTML <= 1.0.2 - Cross-Site Request Forgery to Settings Update
Read the full analysisVulnerability Records

WP2HTML
Author
digitalacornjp
Do you want to get rid of WordPress overheads? Let’s output static HTML and get rid of that overhead. If you use “?” in the permalink, adjust it that use slash-separated. You can select the pages you wish to output in the options screen. Outputs static HTML to the level below the folder where WordPress is installed. https://github.com/digital-acorn-jp/wp2html Usage Click the WP2HTML link in the sidebar, go to the plugins page. Set the options and the pages not generated, the pages to add. Click the Save button. Then you will see a list of paths in bottom of page. Check the paths. Click the Genarate button. Genarated the static HTMLs.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C