MC4WP: Mailchimp for WordPress <= 4.12.0 - Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 4.12.0
- Fixed in:
- 4.12.1
- Disclosed:
- Aug 21, 2026
CVE-2026-4561 on NVD →
MC4WP - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion vulnerability
medium
Missing Authorization to Unauthenticated Arbitrary Subscription Deletion vulnerability
- CVSS:
- 6.5
- Affected:
- up to 4.11.1
- Fixed in:
- 4.12.0
- Disclosed:
- Mar 11, 2026
MC4WP: Mailchimp for WordPress <= 4.11.1 - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to force the form to process unsubscribe actions inste...
- CVSS:
- 6.5
- Affected:
- up to 4.11.1
- Fixed in:
- 4.12.0
- Disclosed:
- Mar 10, 2026
CVE-2026-1781 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.17
unknown
[en] The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...
- Affected:
- up to 4.9.17
- Fixed in:
- 4.9.17
- Disclosed:
- Sep 21, 2024
CVE-2024-8680 on NVD →
MailChimp for Wordpress <= 4.9.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and ab...
- CVSS:
- 4.4
- Affected:
- up to 4.9.16
- Fixed in:
- 4.9.17
- Disclosed:
- Sep 20, 2024
CVE-2024-8680 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16
unknown
[en] The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- Affected:
- 4.9.9 – 4.9.16
- Fixed in:
- 4.9.16
- Disclosed:
- Sep 19, 2024
CVE-2024-8850 on NVD →
MC4WP: Mailchimp for WordPress 4.9.9 - 4.9.16 - Reflected Cross-Site Scripting
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...
- CVSS:
- 6.1
- Affected:
- 4.9.9 – 4.9.16
- Fixed in:
- 4.9.17
- Disclosed:
- Sep 18, 2024
CVE-2024-8850 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.10
unknown
[en] Missing Authorization vulnerability in ibericode MC4WP.This issue affects MC4WP: from n/a through 4.9.9.
- Affected:
- up to 4.9.10
- Fixed in:
- 4.9.10
- Disclosed:
- Jun 11, 2024
CVE-2023-51682 on NVD →
MC4WP <= 4.9.9 - Missing Authorization via listen
medium
The MC4WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'listen' function in versions up to, and including, 4.9.9. This makes it possible for unauthenticated attackers to preview unpublished forms.
- CVSS:
- 5.3
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.10
- Disclosed:
- Dec 27, 2023
CVE-2023-51682 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7
unknown
[en] Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.7
- Disclosed:
- May 20, 2022
CVE-2021-36833 on NVD →
MC4WP: Mailchimp for WordPress <= 4.8.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and abo...
- CVSS:
- 5.5
- Affected:
- up to 4.8.6
- Fixed in:
- 4.8.7
- Disclosed:
- Mar 2, 2022
CVE-2021-36833 on NVD →
MC4WP: Mailchimp for WordPress < 4.8.7 - Cross-Site Scripting
medium
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 5.5
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.7
- Disclosed:
- Mar 2, 2022
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7
unknown
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.7
- Disclosed:
- Mar 2, 2022
MC4WP: Mailchimp for WordPress <= 4.8.4 - Cross-Site Request Forgery
high
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged re...
- CVSS:
- 8.8
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress <= 4.8.4 - Open Redirect
medium
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into...
- CVSS:
- 6.1
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged re...
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into...
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
Authenticated Arbitrary Redirect vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
Unauthorised Actions via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Jun 1, 2021
MC4WP: Mailchimp for WordPress <= 4.1.6 - Reflected Cross-Site Scripting
medium
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- Nov 9, 2019
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7
unknown
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
- Disclosed:
- Nov 9, 2019
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.8
unknown
[en] The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Aug 22, 2019
CVE-2017-18577 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11
unknown
[en] The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.11
- Disclosed:
- Aug 13, 2019
CVE-2016-10871 on NVD →
Mailchimp For WP <= 4.1.7 - Cross-Site Scripting
medium
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
- CVSS:
- 6.1
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Sep 8, 2017
CVE-2017-18577 on NVD →
MailChimp for WordPress <= 4.0.10 - Reflected Cross-Site Scripting
medium
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
- CVSS:
- 6.1
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.11
- Disclosed:
- Dec 13, 2016
CVE-2016-10871 on NVD →
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.11
- Disclosed:
- Dec 9, 2016
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7
unknown
The plugin does not properly sanitise from data, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.7
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions and redirect them to an arbitrary website after
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
unknown
The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions such as empty the logs, dismiss notice and so on
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7
unknown
Usage of the output of add_query_arg() without escaping in various places in the WordPress Backend leads to reflected XSS vulnerability.
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database