plugin

Mailchimp Subscribe Sm Vulnerabilities

7 known security issues reported for the Mailchimp Subscribe Sm WordPress plugin. Most recent disclosed Aug 11, 2026.

3 high 4 medium

Running Mailchimp Subscribe Sm on your site? Check whether your installed version is affected.

Scan your site free

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting

high

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...

CVSS:
7.2
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Aug 11, 2026

CVE-2026-27536 on NVD →

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting via Form Field Values

high

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
7.2
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Jul 31, 2026

CVE-2026-15052 on NVD →

MailChimp Subscribe Forms <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
Jan 15, 2025

CVE-2025-22727 on NVD →

MailChimp Subscribe Forms <= 4.0.9.7 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.0.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with edito...

CVSS:
4.4
Affected:
up to 4.0.9.7
Fixed in:
4.0.9.8
Disclosed:
Aug 9, 2024

CVE-2024-43211 on NVD →

MailChimp Subscribe Forms <= 4.0.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to injec...

CVSS:
4.4
Affected:
up to 4.0.9.1
Fixed in:
4.0.9.2
Disclosed:
May 22, 2023

CVE-2023-33328 on NVD →

MailChimp Subscribe Forms <= 4.0.9.3 - Open Redirect

medium

The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 4.0.9.3. This is due to the application failing to properly verify a user-supplied input parameter. This makes it possible for unauthenticated attackers to exploit this issue and redirect users to arbitra...

CVSS:
6.1
Affected:
up to 4.0.9.3
Fixed in:
4.0.9.4
Disclosed:
May 10, 2023

CVE-2023-32517 on NVD →

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder < 1.2 - Remote Code Execution

high

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder theme for WordPress is vulnerable to Remote Code Execution in versions before 1.2 via the email field. This allows authenticated attackers to execute code on the server.

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Apr 21, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database