Directory Traversal Vulnerability in Easy2Map Plugin for WordPress
CVE-2015-4616

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
8 July 2015

Summary

A directory traversal vulnerability exists in the Easy2Map plugin for WordPress prior to version 1.2.5, specifically in the includes/MapPinImageSave.php file. This flaw enables remote attackers to exploit the 'map_id' parameter, potentially creating arbitrary files on the server by using '../' sequences. This can lead to unauthorized access and escalate the risk of compromising sensitive data and system integrity.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.