Description
WordPress Plugin Easy Forms for MailChimp is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Easy Forms for MailChimp version 6.0.5.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sumofpwn.nl/advisory/2016/easy_forms_for_mailchimp_local_file_inclusion_vulnerability.html
https://wordpress.org/plugins/yikes-inc-easy-mailchimp-extender/changelog/
Related Vulnerabilities
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.7.94)
MySQL CVE-2019-2993 Vulnerability (CVE-2019-2993)
Oracle Database Server CVE-2010-0853 Vulnerability (CVE-2010-0853)
Jenkins Incorrect Authorization Vulnerability (CVE-2023-27903)
MediaWiki Improper Input Validation Vulnerability (CVE-2010-1189)