The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
History

Tue, 08 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibericode
Ibericode mailchimp Top Bar
CPEs cpe:2.3:a:ibericode:mailchimp_top_bar:*:*:*:*:*:wordpress:*:*
Vendors & Products Ibericode
Ibericode mailchimp Top Bar

Wed, 02 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Dvankootem
Dvankootem mailchimp Top Bar
CPEs cpe:2.3:a:dvankootem:mailchimp_top_bar:*:*:*:*:*:*:*:*
Vendors & Products Dvankootem
Dvankootem mailchimp Top Bar
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Description The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title MC4WP: Mailchimp Top Bar <= 1.6.0 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-02T07:35:28.818Z

Updated: 2024-10-02T18:33:31.906Z

Reserved: 2024-09-26T15:18:31.311Z

Link: CVE-2024-9210

cve-icon Vulnrichment

Updated: 2024-10-02T18:33:08.928Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T08:15:03.180

Modified: 2024-10-08T15:34:42.060

Link: CVE-2024-9210

cve-icon Redhat

No data.