XSS Vulnerability in Easy MailChimp Forms Plugin for WordPress
CVE-2014-7152

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 September 2014

Summary

The Easy MailChimp Forms plugin for WordPress contains a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML through the update_options action via the wp-admin/admin-ajax.php file. This vulnerability affects versions 3.0 through 5.0.6 of the plugin, exposing sites to potential exploits if they are not promptly updated or secured. It is crucial for WordPress administrators to ensure that they are running the latest version of the plugin to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.