plugin

Yikes Inc Easy Mailchimp Extender Vulnerabilities

31 known security issues reported for the Yikes Inc Easy Mailchimp Extender WordPress plugin. Most recent disclosed Jun 10, 2024.

2 critical 2 high 9 medium

Running Yikes Inc Easy Mailchimp Extender on your site? Check whether your installed version is affected.

Scan your site free

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] <= 6.9.0 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.

Affected:
up to 6.9.0
Fix:
No patched version reported
Disclosed:
Jun 10, 2024

CVE-2024-35742 on NVD →

Easy Forms for Mailchimp <= 6.9.0 - Missing Authorization

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.9.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.9.0
Fix:
No patched version reported
Disclosed:
Jun 6, 2024

CVE-2024-35742 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] <= 6.9.0 (unfixed + closed)

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.

Affected:
up to 6.9.0
Fix:
No patched version reported
Disclosed:
Jun 4, 2024

CVE-2024-25095 on NVD →

Easy Forms for Mailchimp <= 6.8.10 - Sensitive Information Exposure via logfile

high

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.10 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including mail logs.

CVSS:
7.5
Affected:
up to 6.8.10
Fix:
No patched version reported
Disclosed:
Feb 12, 2024

CVE-2024-25095 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.9.0 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 6.9.0
Fixed in:
6.9.0
Disclosed:
Jan 15, 2024

CVE-2023-4925 on NVD →

Easy Forms for Mailchimp <= 6.8.10 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.8.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...

CVSS:
4.4
Affected:
up to 6.8.10
Fix:
No patched version reported
Disclosed:
Dec 21, 2023

CVE-2023-4925 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.9 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions.

Affected:
up to 6.8.9
Fixed in:
6.8.9
Disclosed:
Aug 10, 2023

CVE-2023-23900 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.9 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 6.8.9
Fixed in:
6.8.9
Disclosed:
Jun 12, 2023

CVE-2023-1323 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.9 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 6.8.9
Fixed in:
6.8.9
Disclosed:
May 30, 2023

CVE-2023-2518 on NVD →

Easy Forms for Mailchimp <= 6.8.8 - Reflected Cross-Site Scripting

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 6.8.8
Fixed in:
6.8.9
Disclosed:
May 22, 2023

CVE-2023-2518 on NVD →

Easy Forms for Mailchimp <= 6.8.8 - Reflected Cross-Site Scripting via 'sql_error'

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql_error' parameter in versions up to, and including, 6.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 6.8.8
Fixed in:
6.8.9
Disclosed:
May 17, 2023

CVE-2023-23900 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.8 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 6.8.8
Fixed in:
6.8.8
Disclosed:
Apr 24, 2023

CVE-2023-1324 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.7 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 6.8.7
Fixed in:
6.8.7
Disclosed:
Apr 17, 2023

CVE-2023-1325 on NVD →

Easy Forms for MailChimp <= 6.8.7 - Reflected Cross-Site Scripting

medium

The Easy Forms for MailChimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the in versions up to, and including, 6.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 6.8.7
Fixed in:
6.8.8
Disclosed:
Mar 29, 2023

CVE-2023-1324 on NVD →

Easy Forms for MailChimp <= 6.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Easy Forms for MailChimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 6.8.6
Fixed in:
6.8.7
Disclosed:
Mar 27, 2023

CVE-2023-1325 on NVD →

Easy Forms for Mailchimp <= 6.8.8 - Authenticated (Administrator+) Cross-Site Scripting via Form Name

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Name in versions up to, and including, 6.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 6.8.8
Fixed in:
6.8.9
Disclosed:
Mar 9, 2023

CVE-2023-1323 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.8.6 (closed)

unknown

[en] The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 6.8.6
Fixed in:
6.8.6
Disclosed:
Jan 24, 2022

CVE-2021-24985 on NVD →

Easy Forms for Mailchimp <= 6.8.5 - Reflected Cross-Site Scripting

medium

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 6.8.6
Fixed in:
6.8.6
Disclosed:
Dec 21, 2021

CVE-2021-24985 on NVD →

Easy Forms for Mailchimp <= 6.6.2 - Authenticated Cross-Site Scripting

medium

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.4
Affected:
up to 6.6.3
Fixed in:
6.6.3
Disclosed:
Mar 29, 2020

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.6.3 (closed)

unknown

The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 6.6.3
Fixed in:
6.6.3
Disclosed:
Mar 29, 2020

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.6.3 (closed)

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability discovered in WordPress Easy Forms for Mailchimp plugin (versions <= 6.6.2).

Affected:
up to 6.6.3
Fixed in:
6.6.3
Disclosed:
Feb 26, 2020

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.5.3 (closed)

unknown

[en] The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

Affected:
up to 6.5.3
Fixed in:
6.5.3
Disclosed:
Aug 22, 2019

CVE-2019-15318 on NVD →

Easy Forms for Mailchimp <= 6.5.2 - Code Injection

critical

The Easy Forms for Mailchimp plugin before 6.5.3 for WordPress has code injection via the admin input field.

CVSS:
9.8
Affected:
up to 6.5.3
Fixed in:
6.5.3
Disclosed:
Jul 1, 2019

CVE-2019-15318 on NVD →

Easy Forms for Mailchimp < 6.1 - Local File Inclusion

critical

The Easy Forms for Mailchimp for WordPress is vulnerable to Local File Inclusion in versions before 6.1 via the vulnerable parameter 'section'. This allows attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...

CVSS:
9.1
Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
Jul 13, 2016

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.1 (closed)

unknown

Because of this vulnerability, attackers can run arbitrary PHP code. Update the plugin.

Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
Jul 13, 2016

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.1 (closed)

unknown

The Easy Forms for Mailchimp for WordPress is vulnerable to Local File Inclusion in versions before 6.1 via the vulnerable parameter 'section'. This allows attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...

Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
Jul 13, 2016

Easy Forms for Mailchimp 3.0 - 5.0.6 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

CVSS:
7.2
Affected:
3.0 – 5.0.6
Fixed in:
5.0.7
Disclosed:
Sep 26, 2014

CVE-2014-7152 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] >= 3.0 - <= 5.0.6 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

Affected:
3.0 – 5.0.6
Fixed in:
5.0.6
Disclosed:
Sep 26, 2014

CVE-2014-7152 on NVD →

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.1 (closed)

unknown

The Easy Forms for Mailchimp WordPress plugin was affected by a Local File Inclusion (LFI) security vulnerability.

Affected:
up to 6.1
Fixed in:
6.1

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 5.0.4 (closed)

unknown
Affected:
up to 5.0.4
Fixed in:
5.0.4

Easy Forms for Mailchimp [yikes-inc-easy-mailchimp-extender] < 6.6.3 (closed)

unknown

The Easy Forms for Mailchimp WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 6.6.3
Fixed in:
6.6.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database