Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Mailchimp For Wp — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
mailchimp-for-wp
- 1000000+ instalaciones activas
emailformmailchimpnewslettersubscribe
Estado de mantenimiento
- Última versión conocida: 4.13.1
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
7 CVEs conocidos registrados para Mailchimp For Wp.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-8680
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.17 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,5
|
< 4.9.17
|
4.9.17 |
2024-09-20 |
✓ corregido en la última versión
|
|
CVE-2024-8850
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
4.9.9–4.9.16
|
4.9.16 |
2024-09-18 |
✓ corregido en la última versión
|
|
CVE-2023-51682
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.9.10 |
Falta de control de autorización |
Media
5,3
|
< 4.9.10
|
4.9.10 |
2023-12-27 |
✓ corregido en la última versión
|
|
CVE-2021-36833
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 4.8.7
|
4.8.7 |
2022-03-02 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 |
— |
Desconocido
|
< 4.8.7
|
4.8.7 |
2022-03-02 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
2021-06-01 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
2021-06-01 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
2021-06-01 |
✓ corregido en la última versión
|
CVE-2024-8680
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-8850
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-51682
Update the WordPress MC4WP plugin to the latest available version (at least 4.9.10).
Rafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress MC4WP Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 4.9.10.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-36833
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
Unauthorised Actions via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
Authenticated Arbitrary Redirect vulnerability discovered by WPScanTeam in WordPress MC4WP plugin (versions <= 4.8.4).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers to dismiss notices and delete log files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 10 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
2021-06-01 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7 |
— |
Desconocido
|
< 4.1.7
|
4.1.7 |
2019-11-09 |
✓ corregido en la última versión
|
|
CVE-2017-18577
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 4.1.8
|
4.1.8 |
2017-09-08 |
✓ corregido en la última versión
|
|
CVE-2016-10871
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 4.0.11
|
4.0.11 |
2016-12-13 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11 |
— |
Desconocido
|
< 4.0.11
|
4.0.11 |
2016-12-09 |
✓ corregido en la última versión
|
|
CVE-2026-1781
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.12.0 |
— |
Desconocido
|
< 4.12.0
|
4.12.0 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7 |
— |
Desconocido
|
< 4.8.7
|
4.8.7 |
— |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
— |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5 |
— |
Desconocido
|
< 4.8.5
|
4.8.5 |
— |
✓ corregido en la última versión
|
|
—
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7 |
— |
Desconocido
|
< 4.1.7
|
4.1.7 |
— |
✓ corregido en la última versión
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2017-18577
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2016-10871
The MC4WP: Mailchimp for WordPress WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.0.11
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2026-1781
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to force the form to process unsubscribe actions instead of subscribe actions. This makes it possible for unauthenticated attackers to arbitrarily unsubscribe any email address from the connected Mailchimp audience via the `_mc4wp_action` parameter, granted they can obtain the form ID (which is publicly exposed in the HTML source).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.7
The plugin does not properly sanitise from data, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions and redirect them to an arbitrary website after
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.8.5
The plugin did not properly check for CSRF in some of its actions handled by the listen_for_actions method (hooked as admin_init), allowing attackers to make logged in users with the manage_options capability do unwanted actions such as empty the logs, dismiss notice and so on
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] < 4.1.7
Usage of the output of add_query_arg() without escaping in various places in the WordPress Backend leads to reflected XSS vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Mailchimp For Wp actualizado — 4.13.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas