Description
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-09-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Mailchimp for WordPress plugin contains an insufficiently sanitized dynamic content tag that allows an attacker to inject arbitrary JavaScript into a page. Because the tag value is reflected back to the browser without proper escaping, an unauthenticated user can cause malicious scripts to execute when another user views a page that includes the tag. This class of vulnerability can be used for defacement, credential theft, or privilege escalation in user sessions. The weakness is a classic reflected XSS flaw (CWE‑79).

Affected Systems

The vulnerability affects the MC4WP plugin for WordPress that is authored by dvankooten, in any version up to and including 4.14.0. Sites running those legacy plugin versions are susceptible unless the code is patched or the feature is disabled.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated user crafting a link or form that includes malicious payloads in the ‘data’ tag and convincing a legitimate WordPress user to click it, at which point the zero‑trust script would execute in the user’s browser. Without additional protection, a successful exploit could lead to session hijacking or malicious site manipulation.

Generated by OpenCVE AI on September 19, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MC4WP plugin to version 4.14.1 or newer to remove the vulnerable tag handling code.
  • If an immediate upgrade is not feasible, disable the use of dynamic content tags or restrict the capability to trusted administrators only, thereby preventing unvalidated data from reaching end‑users.
  • Add a Content Security Policy that disallows inline scripts or untrusted origins, which mitigates the impact of any remaining reflected payloads.
  • Ensure WordPress itself is kept up‑to‑date and that only secure, signed plugins are installed, reducing the overall attack surface.

Generated by OpenCVE AI on September 19, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Dvankooten
Dvankooten mc4wp: Mailchimp For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Dvankooten
Dvankooten mc4wp: Mailchimp For Wordpress
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dynamic Content Tag
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Dvankooten Mc4wp: Mailchimp For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:20.441Z

Reserved: 2026-09-09T15:56:01.475Z

Link: CVE-2026-87917

cve-icon Vulnrichment

Updated: 2026-09-19T13:50:28.679Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.917

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-87917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')