The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3. This vulnerability is caused by insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. The technical impact of this vulnerability is tha [truncated]
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. The vulnerability allows unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DAT [truncated]