CVE · Medium

CVE-2024-8850 — MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8850 MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 4.9.9–4.9.16 4.9.16 2024-09-18

CVE-2024-8850

The MC4WP: Mailchimp for WordPress plugin versions 4.9.9 through 4.9.16 are susceptible to Reflected Cross-Site Scripting (XSS) attacks when the 'email' parameter is used with placeholders like {email}. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject malicious scripts, which can be executed if a user clicks on a crafted link or performs a related action.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.