peter bassill · operator
$ cve CVE-2015-7669 JSON

CVE-2015-7669

9.8
CRITICAL · CVSS 3.0 · EPSS 7.1% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.11% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2017-12-27
Last modified2026-06-17

Affected (1)

VendorProduct
easy2mapeasy2map

References

→ the Explorer  ·  watch your stack  ·  NVD