Yikesinc

Easy Forms For Mailchimp

8 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Published 15.01.2024 16:15:11
  • Last modified 11.06.2025 17:15:35

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

  • EPSS 0.19%
  • Published 10.08.2023 12:15:10
  • Last modified 21.11.2024 07:47:03

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions.

  • EPSS 0.11%
  • Published 12.06.2023 18:15:09
  • Last modified 03.01.2025 15:15:09

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html cap...

Exploit
  • EPSS 12.55%
  • Published 30.05.2023 08:15:10
  • Last modified 10.01.2025 21:15:11

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high p...

Exploit
  • EPSS 0.18%
  • Published 24.04.2023 19:15:09
  • Last modified 04.02.2025 19:15:27

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as ...

Exploit
  • EPSS 0.27%
  • Published 17.04.2023 13:15:38
  • Last modified 05.03.2025 19:15:27

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and ab...

Exploit
  • EPSS 0.35%
  • Published 24.01.2022 08:15:09
  • Last modified 21.11.2024 05:54:08

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

  • EPSS 0.99%
  • Published 22.08.2019 13:15:13
  • Last modified 21.11.2024 04:28:26

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.