CVE-2023-4925
- EPSS 0.08%
- Veröffentlicht 15.01.2024 16:15:11
- Zuletzt bearbeitet 11.06.2025 17:15:35
The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2023-23900
- EPSS 0.19%
- Veröffentlicht 10.08.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:47:03
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions.
CVE-2023-1323
- EPSS 0.11%
- Veröffentlicht 12.06.2023 18:15:09
- Zuletzt bearbeitet 03.01.2025 15:15:09
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html cap...
CVE-2023-2518
- EPSS 12.55%
- Veröffentlicht 30.05.2023 08:15:10
- Zuletzt bearbeitet 10.01.2025 21:15:11
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high p...
CVE-2023-1324
- EPSS 0.18%
- Veröffentlicht 24.04.2023 19:15:09
- Zuletzt bearbeitet 04.02.2025 19:15:27
The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as ...
CVE-2023-1325
- EPSS 0.27%
- Veröffentlicht 17.04.2023 13:15:38
- Zuletzt bearbeitet 05.03.2025 19:15:27
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and ab...
CVE-2021-24985
- EPSS 0.35%
- Veröffentlicht 24.01.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:08
The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVE-2019-15318
- EPSS 0.99%
- Veröffentlicht 22.08.2019 13:15:13
- Zuletzt bearbeitet 21.11.2024 04:28:26
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.