CVE Database /
CVE-2024-8850
CVE · Medium
CVE-2024-8850 — MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-8850
|
MC4WP: Mailchimp for WordPress [mailchimp-for-wp] >= 4.9.9 - <= 4.9.16 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
4.9.9–4.9.16
|
4.9.16 |
2024-09-18 |
—
|
CVE-2024-8850
The MC4WP: Mailchimp for WordPress plugin versions 4.9.9 through 4.9.16 are susceptible to Reflected Cross-Site Scripting (XSS) attacks when the 'email' parameter is used with placeholders like {email}. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject malicious scripts, which can be executed if a user clicks on a crafted link or performs a related action.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings