Directory Traversal Vulnerability in Easy2Map Plugin for WordPress
CVE-2015-4616
Currently unrated
Summary
A directory traversal vulnerability exists in the Easy2Map plugin for WordPress prior to version 1.2.5, specifically in the includes/MapPinImageSave.php file. This flaw enables remote attackers to exploit the 'map_id' parameter, potentially creating arbitrary files on the server by using '../' sequences. This can lead to unauthorized access and escalate the risk of compromising sensitive data and system integrity.
References
EPSS Score
9% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved