CVE-2015-9451: Sizmic Plugmatter Optin Feature Box

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

Affected products

  • Sizmic Plugmatter Optin Feature Box: before 2.0.14 (fixed in 2.0.14)

Published 2019-10-07. Last modified 2026-06-17.