Impact
The PluginOps MailChimp Subscribe Forms plugin has improper neutralization of input during web page generation, allowing stored cross‑site scripting. An attacker can embed malicious JavaScript that is saved as part of the form and then delivered to any visitor who views the page containing the form, leading to a compromise of the victim’s browser. This weakness is identified as CWE‑79.
Affected Systems
Any WordPress site running the MailChimp Subscribe Forms plugin version 4.1 or earlier, as identified by the CNA entry PluginOps:MailChimp Subscribe Forms.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity. Its EPSS score is below 1 %, indicating a very low probability of exploitation at the time of analysis. The plugin is not listed in CISA’s KEV catalog, and the CVE description does not reference any public exploits. Based on the description, an attacker can inject malicious payloads into the plugin’s form fields, which are then stored and served to other visitors, executing in their browsers without requiring server‑side privileges.
OpenCVE Enrichment
EUVD