S4E just found a medium-severity finding from host header injection vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2015-2755 Scanner

Detects 'Cross-Site Request Forgery (CSRF)' vulnerability in AB Google Map Travel (AB-MAP) plugin for WordPress affects v. before 4.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-2755
6.8
CVSS

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The AB Google Map Travel (AB-MAP) plugin is a tool designed for use with the WordPress platform. This plugin allows users to add customized maps to their WordPress website with ease. With the AB-MAP plugin, users can manually add markers, customize map colors, and even add their own KML files. This functionality makes AB-MAP an essential tool for businesses, bloggers, and other WordPress website owners who wish to display visual data on their website. 

One vulnerability that has been detected in the AB-MAP plugin is the CVE-2015-2755 vulnerability. This vulnerability permits attackers to conduct cross-site request forgery (CSRF) attacks, which can lead to an attacker hijacking the authentication of administrators and carrying out cross-site scripting (XSS) attacks. The vulnerability arises from the lat (Latitude), long (Longitude), map_width, map_height, or zoom (Map Zoom) parameters in the ab_map_options page to wp-admin/admin.php.

When this vulnerability is exploited, it can lead to severe implications for the website owner and users. An attacker could gain access to highly sensitive user data, hijack user accounts, or even steal website login credentials. With the advent of GDPR and similar privacy regulations, non-compliance with such standards could lead to legal repercussions and, most importantly, brand damage. 

Thanks to the pro features of the s4e.io platform, website owners can quickly and easily learn about vulnerabilities in their digital assets. On this platform, users can receive real-time alerts, track vulnerabilities over time, and even export vulnerability data for use in reports. By using this platform, WordPress website owners can protect their digital assets and keep their online presence secure. It is better to be safe than sorry by being proactive in securing digital assets than waiting for them to be compromised and regretting it.

 

REFERENCES

Solution Advice

To protect against this vulnerability, WordPress website owners should take the following precautions:

  • Make sure to update the AB-MAP plugin to the latest version available.
  • Use a robust and secure password where possible.
  • Avoid storing login details or other sensitive data, including session tokens, in a browser’s cache or local storage.
  • Ensure that hosting providers implement encrypted connections to secure user data.
  • Consider using a security plugin such as WordFence to help identify and protect against vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-2755 scanner - Cross-Site Request Forgery (CSRF) vulnerability in AB Google Map Travel (AB-MAP) plugin for WordPress | S4E