Impact
The Mailchimp for WordPress plugin contains an insufficiently sanitized dynamic content tag that allows an attacker to inject arbitrary JavaScript into a page. Because the tag value is reflected back to the browser without proper escaping, an unauthenticated user can cause malicious scripts to execute when another user views a page that includes the tag. This class of vulnerability can be used for defacement, credential theft, or privilege escalation in user sessions. The weakness is a classic reflected XSS flaw (CWE‑79).
Affected Systems
The vulnerability affects the MC4WP plugin for WordPress that is authored by dvankooten, in any version up to and including 4.14.0. Sites running those legacy plugin versions are susceptible unless the code is patched or the feature is disabled.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated user crafting a link or form that includes malicious payloads in the ‘data’ tag and convincing a legitimate WordPress user to click it, at which point the zero‑trust script would execute in the user’s browser. Without additional protection, a successful exploit could lead to session hijacking or malicious site manipulation.
OpenCVE Enrichment