CVE-2015-4617: EASY2MAP EASY2MAP-Photos
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.
Affected products
- EASY2MAP EASY2MAP-Photos: version 1.09 only
Published 2019-02-15. Last modified 2026-06-17.