CVE-2019-15318: Yikesinc Easy Forms For Mailchimp

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

Affected products

  • Yikesinc Easy Forms For Mailchimp: before 6.5.3 (fixed in 6.5.3)

Published 2019-08-22. Last modified 2026-06-17.