Description
WordPress Plugin Easy Forms for MailChimp is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Easy Forms for MailChimp version 6.0.5.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sumofpwn.nl/advisory/2016/easy_forms_for_mailchimp_local_file_inclusion_vulnerability.html
https://wordpress.org/plugins/yikes-inc-easy-mailchimp-extender/changelog/
Related Vulnerabilities
WordPress Plugin WP Easy Post Types Cross-Site Scripting (1.4.3)
WordPress Plugin Author Periodic Report Cross-Site Scripting (1.0)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4789)
Liferay version older than 7.0
WordPress Plugin All-in-One Video Gallery Local File Inclusion (2.4.9)