plugin

Easy2Map Vulnerabilities

6 known security issues reported for the Easy2Map WordPress plugin. Most recent disclosed Oct 5, 2015.

2 critical 2 medium

Running Easy2Map on your site? Check whether your installed version is affected.

Scan your site free

Easy2Map <= 1.2.9 - Directory Traversal and Local File Inclusion

critical

Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."

CVSS:
9.8
Affected:
up to 1.2.9
Fixed in:
1.3.0
Disclosed:
Oct 5, 2015

CVE-2015-7669 on NVD →

Easy2Map <= 1.2.9 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.

CVSS:
6.1
Affected:
up to 1.2.9
Fixed in:
1.3.0
Disclosed:
Oct 5, 2015

CVE-2015-7668 on NVD →

Easy2Map [easy2map] < 1.2.5 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jul 8, 2015

CVE-2015-4614 on NVD →

Easy2Map [easy2map] < 1.2.5 (closed)

unknown

[en] Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jul 8, 2015

CVE-2015-4616 on NVD →

Easy2Map <= 1.2.4 - SQL Injection

critical

Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.

CVSS:
9.8
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jun 8, 2015

CVE-2015-4614 on NVD →

Easy2Map <= 1.2.4 - Directory Traversal

medium

Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.

CVSS:
6.5
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jun 8, 2015

CVE-2015-4616 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database