Description
WordPress Plugin MailChimp for WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin MailChimp for WooCommerce version 2.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin File Manager Cross-Site Scripting (2.9)
WordPress 4.7.x Cross-Domain Flash Injection Vulnerability (4.7 - 4.7.8)
WordPress Plugin Subscribe Form Remote Command Execution (1.1)
PHP Other Vulnerability (CVE-2016-4343)
WordPress Direct Request ('Forced Browsing') Vulnerability (CVE-2005-1688)