Arbitrary File Inclusion Vulnerabilities in Easy2Map Plugin for WordPress

Arbitrary File Inclusion Vulnerabilities in Easy2Map Plugin for WordPress

CVE-2015-7669 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."

Learn more about our Wordpress Pen Testing.