← WordPress Vulnerabilities
WordPress security by component

Easy Forms for Mailchimp

Easy Forms for Mailchimp is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 10, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: yikes-inc-easy-mailchimp-extender

CVE-2024-35742: Easy Forms for Mailchimp: A security weakness

Easy Forms for Mailchimp is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJun 10, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 10, 2024 CVE-2024-35742
Easy Forms for Mailchimp: A security weakness
Easy Forms for Mailchimp is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.3
Jun 04, 2024 CVE-2024-25095
Easy Forms for Mailchimp: A security weakness
Easy Forms for Mailchimp is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 10, 2023 CVE-2023-23900
Yikes Inc Easy Mailchimp Extender: Cross-site scripting
Yikes Inc Easy Mailchimp Extender is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.8
NVD6.1
Aug 22, 2019 CVE-2019-15318
Yikes Inc Easy Mailchimp Extender: Code execution
Yikes Inc Easy Mailchimp Extender is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Sep 26, 2014 CVE-2014-7152
Yikes Inc Easy Mailchimp Extender: Cross-site scripting
Yikes Inc Easy Mailchimp Extender is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3