CVE-2015-2755: XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) mapwidth, (4) mapheight, or (5) zoom (Map Zoom) parameter in the abmapoptions page to wp-admin/admin.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2755?
CVE-2015-2755 has a medium severity level, indicating a moderate risk to affected systems.
How do I fix CVE-2015-2755?
To fix CVE-2015-2755, update the AB Google Map Travel plugin to version 4.0 or later.
What types of attacks are associated with CVE-2015-2755?
CVE-2015-2755 is associated with cross-site request forgery (CSRF) attacks that can lead to cross-site scripting (XSS) vulnerabilities.
Which versions of the AB Google Map Travel plugin are affected by CVE-2015-2755?
CVE-2015-2755 affects the AB Google Map Travel plugin versions prior to 4.0.
Who can exploit CVE-2015-2755?
CVE-2015-2755 can be exploited by remote attackers who aim to perform unauthorized actions on behalf of administrators.