Description
WordPress Plugin Easy Forms for MailChimp is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Easy Forms for MailChimp version 6.0.5.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sumofpwn.nl/advisory/2016/easy_forms_for_mailchimp_local_file_inclusion_vulnerability.html
https://wordpress.org/plugins/yikes-inc-easy-mailchimp-extender/changelog/
Related Vulnerabilities
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4203)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-2608)
WordPress Plugin myGallery Remote File Include (1.4b4)
WordPress Improper Input Validation Vulnerability (CVE-2018-1000773)
WordPress Plugin Store Locator Plus for WordPress SQL Injection (3.8.6)