rootpwn

medium · CVSS v3 6.1 · EPSS 0.00215

CVE-2026-87917

The MC4WP: Mailchimp for WordPress plugin contains a Reflected Cross-Site Scripting vulnerability via the 'data' Dynamic Content Tag in vers

Overview

The MC4WP: Mailchimp for WordPress plugin contains a Reflected Cross-Site Scripting vulnerability via the 'data' Dynamic Content Tag in versions up to and including 4.14.0. This flaw arises from insufficient input sanitization and output escaping. It matters because unauthenticated attackers can trick users into clicking specially crafted links to execute arbitrary web scripts in their browser context.

Description

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Impact

This vulnerability impacts the integrity and confidentiality of user sessions on vulnerable WordPress sites by allowing arbitrary script execution within a victim's browser session. Unauthenticated attackers can potentially hijack user sessions, steal sensitive data, or perform unauthorized actions on behalf of the victim. System administrators and users interacting with the WordPress dashboard or frontend forms are primarily at risk.

Remediation

Update the MC4WP: Mailchimp for WordPress plugin to version 4.14.1 or later where output escaping and input sanitization have been properly implemented. Implement Web Application Firewall (WAF) rules to detect and block suspicious query parameters associated with reflected cross-site scripting attempts. Monitor plugin change logs and maintain a strict patching cadence for all third-party WordPress components.

Risk context

The vulnerability is rated as medium severity with a CVSS v3 score of 6.1, indicating a moderate technical risk. The current EPSS score is 0.00215, suggesting a relatively low probability of active exploitation in the wild at this time, though defenders should still prioritize timely remediation.

Affected products

  • MC4WP Mailchimp for WordPress plugin

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
EPSS
0.00215

WordPress Plugin XSS Reflected XSS Web Security Input Sanitization

← All CVEs