WordPress · Eesy Id2Wp · CVE-2026-77193
**Name of the Vulnerable Software and Affected Versions**
eesy ID2WP – Publish InDesign HTML5 versions prior to 1.0.4
**Description**
The plugin is subject to Path Traversal, a condition where an attacker can access files and directories that are stored outside the web root folder. Unauthenticated attackers can exploit this by using the `id2wp path` parameter to read arbitrary files on the server, potentially exposing sensitive information.
**Recommendations**
Update the plugin to a version newer than 1.0.3.
Avoid using the `id2wp path` parameter until the update is applied.