Description
WordPress Plugin Easy Forms for Mailchimp is prone to a vulnerability that lets attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Easy Forms for Mailchimp version 6.5.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.5.3 or latest
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4296)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.3)
WordPress Plugin Custom CSS Pro Cross-Site Request Forgery (1.0.3)
Oracle Database Server CVE-2009-1985 Vulnerability (CVE-2009-1985)
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.6.01)