Description
WordPress Plugin ChimpMate-WordPress MailChimp Assistant is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin ChimpMate-WordPress MailChimp Assistant version 1.3.2 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
Microsoft SQL Server CVE-2023-21704 Vulnerability (CVE-2023-21704)
WordPress Plugin ZTR Zeumic Work Timer Multiple Unspecified Vulnerabilities (1.0.6)
WordPress Plugin Podlove Podcast Publisher SQL Injection (2.5.3)
Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556)