Easy2Map Photos <= 1.0.9 - SQL Injection
critical
Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables. CVE-2015-10126 appears to be a duplicate of this issue.
- CVSS:
- 9.8
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Jun 8, 2015
CVE-2015-4615 on NVD →
Easy2map-photos <= 1.0.9 - Path Traversal
medium
Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
- CVSS:
- 5.3
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Jun 8, 2015
CVE-2015-4617 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database