MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting
high
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 7.2
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.4
- Disclosed:
- Aug 11, 2026
CVE-2026-27536 on NVD →
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting via Form Field Values
high
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.2
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.4
- Disclosed:
- Jul 31, 2026
CVE-2026-15052 on NVD →
MailChimp Subscribe Forms <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 4.1
- Fixed in:
- 4.2
- Disclosed:
- Jan 15, 2025
CVE-2025-22727 on NVD →
MailChimp Subscribe Forms <= 4.0.9.7 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.0.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with edito...
- CVSS:
- 4.4
- Affected:
- up to 4.0.9.7
- Fixed in:
- 4.0.9.8
- Disclosed:
- Aug 9, 2024
CVE-2024-43211 on NVD →
MailChimp Subscribe Forms <= 4.0.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to injec...
- CVSS:
- 4.4
- Affected:
- up to 4.0.9.1
- Fixed in:
- 4.0.9.2
- Disclosed:
- May 22, 2023
CVE-2023-33328 on NVD →
MailChimp Subscribe Forms <= 4.0.9.3 - Open Redirect
medium
The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 4.0.9.3. This is due to the application failing to properly verify a user-supplied input parameter. This makes it possible for unauthenticated attackers to exploit this issue and redirect users to arbitra...
- CVSS:
- 6.1
- Affected:
- up to 4.0.9.3
- Fixed in:
- 4.0.9.4
- Disclosed:
- May 10, 2023
CVE-2023-32517 on NVD →
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder < 1.2 - Remote Code Execution
high
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder theme for WordPress is vulnerable to Remote Code Execution in versions before 1.2 via the email field. This allows authenticated attackers to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Apr 21, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database