OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-77193 (CVSS 7.5)

NVD · officialPublished Sep 24, 2026Risk 23/100EPSS 0.4%

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS
7.5
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:NoneA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source