VDB
CVE-2015-2755
CVE-2015-2755
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.
EPSS 3.83% · 89.6th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
3.83%
89.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| ab_google_map_travel_project | ab_google_map_travel | 0 |
Timeline
- Apr 1, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- Nuclei Template exploit
- http://packetstormsecurity.com/files/131155/WordPress-Google-Map-Travel-3.4-XSS-CSRF.html exploit
- https://wordpress.org/plugins/ab-google-map-travel/changelog/ patch
- http://www.securityfocus.com/archive/1/534954/100/0/threaded technical
- http://www.securityfocus.com/archive/1/535026/100/0/threaded technical
- http://www.securityfocus.com/bid/71417 technical
- http://packetstormsecurity.com/files/130960/WordPress-AB-Google-Map-Travel-CSRF-XSS.html url
- https://nvd.nist.gov/vuln/detail/CVE-2015-2755 advisory
- https://wordpress.org/plugins/ab-google-map-travel/changelog url