Impact
The Connect Contact Form 7 and Mailchimp plugin for WordPress contains a stored Cross‑Site Scripting flaw (CWE‑79). An unauthenticated attacker can submit a contact form that includes malicious script payloads in Mailchimp merge field values. The input is insufficiently sanitized and output escaped, so the payload is stored in the database. It is executed only when a privileged administrator performs a Contact Lookup for the email address submitted through the form, thereby deferring script execution until an administrator views the entry.
Affected Systems
WordPress sites that have the rnzo Connect Contact Form 7 and Mailchimp plugin installed at version 0.9.78.06 or earlier are vulnerable. Any site using a newer release is not affected.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog. The attack does not require authentication to inject the malicious payload, but execution occurs only when an administrator performs a contact lookup. Consequently the threat is focused on privileged users, and while overall exploitation probability is low, a seed entry can lead to remote script execution in the administrator’s browser.
OpenCVE Enrichment