Easy2Map <= 1.2.9 - Directory Traversal and Local File Inclusion
critical
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."
- CVSS:
- 9.8
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 5, 2015
CVE-2015-7669 on NVD →
Easy2Map <= 1.2.9 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 5, 2015
CVE-2015-7668 on NVD →
Easy2Map [easy2map] < 1.2.5 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 8, 2015
CVE-2015-4614 on NVD →
Easy2Map [easy2map] < 1.2.5 (closed)
unknown
[en] Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 8, 2015
CVE-2015-4616 on NVD →
Easy2Map <= 1.2.4 - SQL Injection
critical
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.
- CVSS:
- 9.8
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jun 8, 2015
CVE-2015-4614 on NVD →
Easy2Map <= 1.2.4 - Directory Traversal
medium
Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.
- CVSS:
- 6.5
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jun 8, 2015
CVE-2015-4616 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database