WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Mailchimp For Wp?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Mailchimp For Wp — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: mailchimp-for-wp
  • 1000000+ instalaciones activas

emailformmailchimpnewslettersubscribe

Estado de mantenimiento

  • Última versión conocida: 4.13.1
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

7 CVEs conocidos registrados para Mailchimp For Wp.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-8680 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.17 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,5 < 4.9.17 4.9.17 2024-09-20 ✓ corregido en la última versión
CVE-2024-8850 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 4.9.9–4.9.16 4.9.16 2024-09-18 ✓ corregido en la última versión
CVE-2023-51682 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.10 Falta de control de autorización Media 5,3 < 4.9.10 4.9.10 2023-12-27 ✓ corregido en la última versión
CVE-2021-36833 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 4.8.7 4.8.7 2022-03-02 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 Desconocido < 4.8.7 4.8.7 2022-03-02 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 2021-06-01 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 2021-06-01 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 2021-06-01 ✓ corregido en la última versión

CVE-2024-8680

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-8850

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-51682

Update the WordPress MC4WP plugin to the latest available version (at least 4.9.10). Rafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress MC4WP Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 4.9.10. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-36833

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

Unauthorised Actions via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

Authenticated Arbitrary Redirect vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 10 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 2021-06-01 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7 Desconocido < 4.1.7 4.1.7 2019-11-09 ✓ corregido en la última versión
CVE-2017-18577 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.1.8 4.1.8 2017-09-08 ✓ corregido en la última versión
CVE-2016-10871 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.0.11 4.0.11 2016-12-13 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11 Desconocido < 4.0.11 4.0.11 2016-12-09 ✓ corregido en la última versión
CVE-2026-1781 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.12.0 Desconocido < 4.12.0 4.12.0 0000-00-00 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 Desconocido < 4.8.7 4.8.7 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 Desconocido < 4.8.5 4.8.5 ✓ corregido en la última versión
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7 Desconocido < 4.1.7 4.1.7 ✓ corregido en la última versión

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2017-18577

The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2016-10871

The MC4WP: Mailchimp for WordPress WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2026-1781

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to force the form to process unsubscribe actions instead of subscribe actions. This makes it possible for unauthenticated attackers to arbitrarily unsubscribe any email address from the connected Mailchimp audience via the `_mc4wp_action` parameter, granted they can obtain the form ID (which is publicly exposed in the HTML source).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7

The plugin does not properly sanitise from data, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions and redirect them to an arbitrary website after

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5

The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions such as empty the logs, dismiss notice and so on

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7

Usage of the output of add_query_arg() without escaping in various places in the WordPress Backend leads to reflected XSS vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Mailchimp For Wp actualizado — 4.13.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.