CVE-2015-4617: EASY2MAP EASY2MAP-Photos

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.

Affected products

  • EASY2MAP EASY2MAP-Photos: version 1.09 only

Published 2019-02-15. Last modified 2026-06-17.