CVE-2014-7152: XSS
Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the updateoptions action to wp-admin/admin-ajax.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7152?
CVE-2014-7152 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-7152?
To fix CVE-2014-7152, update the Easy MailChimp Forms plugin to version 5.0.7 or later.
Who is affected by CVE-2014-7152?
CVE-2014-7152 affects users of the Easy MailChimp Forms plugin for WordPress versions 3.0 through 5.0.6.
What type of vulnerability is CVE-2014-7152?
CVE-2014-7152 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
What is the consequence of CVE-2014-7152?
The consequence of CVE-2014-7152 is that attackers can execute arbitrary web scripts or HTML in the context of the user's session.