CVE-2015-7669

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/12/2017
Last modified:
20/04/2025

Description

Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:easy2map:easy2map:*:*:*:*:*:wordpress:*:* 1.3.0 (excluding)