Record summary

CVE-2015-2755 has a selected CVSS score of 6.8; EIP currently links 1 Nuclei template.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress AB Google Map Travel <=3.4 - Stored Cross-Site ScriptingCVSS 6.8

WordPress AB Google Map Travel plugin through 3.4 contains multiple stored cross-site scripting vulnerabilities. The plugin allows an attacker to hijack the administrator authentication for requests via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameters in the ab_map_options page to wp-admin/admin.php.

Impact

Successful exploitation of this vulnerability allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized access, data theft, or defacement.

Remediation

Update to the latest version of the AB Google Map Travel plugin (>=3.5) or apply the vendor-supplied patch to mitigate this vulnerability.

WeaknessesCWE-352
Authorsr3Y3r53
Template tagspacketstormcvecve2015xsswordpresswp-pluginwpab-mapauthenticatedab_google_map_travel_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:ab_google_map_travel_project:ab_google_map_travel:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

7