Description
WordPress Plugin Easy Forms for MailChimp is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Easy Forms for MailChimp version 6.0.5.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sumofpwn.nl/advisory/2016/easy_forms_for_mailchimp_local_file_inclusion_vulnerability.html
https://wordpress.org/plugins/yikes-inc-easy-mailchimp-extender/changelog/
Related Vulnerabilities
WordPress Plugin Mapplic Lite Server-Side Request Forgery (1.0)
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.2)
WordPress Plugin Simple Backup Multiple Vulnerabilities (2.7.11)
Joomla! Core 3.x.x Information Disclosure (3.0.0 - 3.9.19)
WordPress Plugin LBstopattack Cross-Site Request Forgery (1.1.2)