Directory Traversal Vulnerability in Easy2Map Plugin for WordPress
CVE-2015-4616

Currently unrated

Key Information:

Vendor

Wordpress

Status
Vendor
CVE Published:
8 July 2015

What is CVE-2015-4616?

A directory traversal vulnerability exists in the Easy2Map plugin for WordPress prior to version 1.2.5, specifically in the includes/MapPinImageSave.php file. This flaw enables remote attackers to exploit the 'map_id' parameter, potentially creating arbitrary files on the server by using '../' sequences. This can lead to unauthorized access and escalate the risk of compromising sensitive data and system integrity.

References

EPSS Score

11% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-4616 : Directory Traversal Vulnerability in Easy2Map Plugin for WordPress