Beta

Report

Easy MailChimp Forms <= 5.0.6 is vulnerable to XSS

Unauthenticated
Published
2014-09-21

Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

CVSS

Score:7.2

Severity:High

Version: 5.0.6

There is a patch available in v5.0.7 and we strongly recommend you update to this version as soon as possible.