plugin

Mailchimp For Wp Vulnerabilities

30 known security issues reported for the Mailchimp For Wp WordPress plugin. Most recent disclosed Aug 21, 2026.

1 high 12 medium

Running Mailchimp For Wp on your site? Check whether your installed version is affected.

Scan your site free

MC4WP: Mailchimp for WordPress <= 4.12.0 - Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 4.12.0
Fixed in:
4.12.1
Disclosed:
Aug 21, 2026

CVE-2026-4561 on NVD →

MC4WP - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion vulnerability

medium

Missing Authorization to Unauthenticated Arbitrary Subscription Deletion vulnerability

CVSS:
6.5
Affected:
up to 4.11.1
Fixed in:
4.12.0
Disclosed:
Mar 11, 2026

MC4WP: Mailchimp for WordPress <= 4.11.1 - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to force the form to process unsubscribe actions inste...

CVSS:
6.5
Affected:
up to 4.11.1
Fixed in:
4.12.0
Disclosed:
Mar 10, 2026

CVE-2026-1781 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.17

unknown

[en] The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

Affected:
up to 4.9.17
Fixed in:
4.9.17
Disclosed:
Sep 21, 2024

CVE-2024-8680 on NVD →

MailChimp for Wordpress <= 4.9.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and ab...

CVSS:
4.4
Affected:
up to 4.9.16
Fixed in:
4.9.17
Disclosed:
Sep 20, 2024

CVE-2024-8680 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16

unknown

[en] The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

Affected:
4.9.9 – 4.9.16
Fixed in:
4.9.16
Disclosed:
Sep 19, 2024

CVE-2024-8850 on NVD →

MC4WP: Mailchimp for WordPress 4.9.9 - 4.9.16 - Reflected Cross-Site Scripting

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...

CVSS:
6.1
Affected:
4.9.9 – 4.9.16
Fixed in:
4.9.17
Disclosed:
Sep 18, 2024

CVE-2024-8850 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.10

unknown

[en] Missing Authorization vulnerability in ibericode MC4WP.This issue affects MC4WP: from n/a through 4.9.9.

Affected:
up to 4.9.10
Fixed in:
4.9.10
Disclosed:
Jun 11, 2024

CVE-2023-51682 on NVD →

MC4WP <= 4.9.9 - Missing Authorization via listen

medium

The MC4WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'listen' function in versions up to, and including, 4.9.9. This makes it possible for unauthenticated attackers to preview unpublished forms.

CVSS:
5.3
Affected:
up to 4.9.9
Fixed in:
4.9.10
Disclosed:
Dec 27, 2023

CVE-2023-51682 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7

unknown

[en] Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.

Affected:
up to 4.8.7
Fixed in:
4.8.7
Disclosed:
May 20, 2022

CVE-2021-36833 on NVD →

MC4WP: Mailchimp for WordPress <= 4.8.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and abo...

CVSS:
5.5
Affected:
up to 4.8.6
Fixed in:
4.8.7
Disclosed:
Mar 2, 2022

CVE-2021-36833 on NVD →

MC4WP: Mailchimp for WordPress < 4.8.7 - Cross-Site Scripting

medium

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
5.5
Affected:
up to 4.8.7
Fixed in:
4.8.7
Disclosed:
Mar 2, 2022

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7

unknown

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

Affected:
up to 4.8.7
Fixed in:
4.8.7
Disclosed:
Mar 2, 2022

MC4WP: Mailchimp for WordPress <= 4.8.4 - Cross-Site Request Forgery

high

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged re...

CVSS:
8.8
Affected:
up to 4.8.4
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress <= 4.8.4 - Open Redirect

medium

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into...

CVSS:
6.1
Affected:
up to 4.8.4
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged re...

Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into...

Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

Authenticated Arbitrary Redirect vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).

Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

Unauthorised Actions via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).

Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Jun 1, 2021

MC4WP: Mailchimp for WordPress <= 4.1.6 - Reflected Cross-Site Scripting

medium

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 4.1.6
Fixed in:
4.1.7
Disclosed:
Nov 9, 2019

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7

unknown

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 4.1.7
Fixed in:
4.1.7
Disclosed:
Nov 9, 2019

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.8

unknown

[en] The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Aug 22, 2019

CVE-2017-18577 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11

unknown

[en] The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.

Affected:
up to 4.0.11
Fixed in:
4.0.11
Disclosed:
Aug 13, 2019

CVE-2016-10871 on NVD →

Mailchimp For WP <= 4.1.7 - Cross-Site Scripting

medium

The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

CVSS:
6.1
Affected:
up to 4.1.7
Fixed in:
4.1.8
Disclosed:
Sep 8, 2017

CVE-2017-18577 on NVD →

MailChimp for WordPress <= 4.0.10 - Reflected Cross-Site Scripting

medium

The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.

CVSS:
6.1
Affected:
up to 4.0.11
Fixed in:
4.0.11
Disclosed:
Dec 13, 2016

CVE-2016-10871 on NVD →

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 4.0.11
Fixed in:
4.0.11
Disclosed:
Dec 9, 2016

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7

unknown

The plugin does not properly sanitise from data, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 4.8.7
Fixed in:
4.8.7

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions and redirect them to an arbitrary website after

Affected:
up to 4.8.5
Fixed in:
4.8.5

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

unknown

The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions such as empty the logs, dismiss notice and so on

Affected:
up to 4.8.5
Fixed in:
4.8.5

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7

unknown

Usage of the output of add_query_arg() without escaping in various places in the WordPress Backend leads to reflected XSS vulnerability.

Affected:
up to 4.1.7
Fixed in:
4.1.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database