medium · CVSS v3 6.1 · EPSS 0.00215
CVE-2026-87917
The MC4WP: Mailchimp for WordPress plugin contains a Reflected Cross-Site Scripting vulnerability via the 'data' Dynamic Content Tag in vers
Overview
The MC4WP: Mailchimp for WordPress plugin contains a Reflected Cross-Site Scripting vulnerability via the 'data' Dynamic Content Tag in versions up to and including 4.14.0. This flaw arises from insufficient input sanitization and output escaping. It matters because unauthenticated attackers can trick users into clicking specially crafted links to execute arbitrary web scripts in their browser context.
Description
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Impact
This vulnerability impacts the integrity and confidentiality of user sessions on vulnerable WordPress sites by allowing arbitrary script execution within a victim's browser session. Unauthenticated attackers can potentially hijack user sessions, steal sensitive data, or perform unauthorized actions on behalf of the victim. System administrators and users interacting with the WordPress dashboard or frontend forms are primarily at risk.
Remediation
Update the MC4WP: Mailchimp for WordPress plugin to version 4.14.1 or later where output escaping and input sanitization have been properly implemented. Implement Web Application Firewall (WAF) rules to detect and block suspicious query parameters associated with reflected cross-site scripting attempts. Monitor plugin change logs and maintain a strict patching cadence for all third-party WordPress components.
Risk context
The vulnerability is rated as medium severity with a CVSS v3 score of 6.1, indicating a moderate technical risk. The current EPSS score is 0.00215, suggesting a relatively low probability of active exploitation in the wild at this time, though defenders should still prioritize timely remediation.
Affected products
- MC4WP Mailchimp for WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- —
- EPSS
- 0.00215