Extension WordPress
Vulnérabilités MC4WP: Mailchimp for WordPress
Cette page rassemble les failles publiées pour MC4WP: Mailchimp for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MC4WP: Mailchimp for WordPress
11 fiches
MC4WP: Mailchimp for WordPress <= 4.11.1 – Missing Authorization to Unauthenticated Arbitrary Subscription Deletion
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to…
*-4.11.1
4.12.0
10/03/2026
MailChimp for Wordpress <= 4.9.16 – Authenticated (Administrator+) Stored Cross-Site Scripting
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.9.16
4.9.17
20/09/2024
MC4WP: Mailchimp for WordPress 4.9.9 – 4.9.16 – Reflected Cross-Site Scripting
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input…
4.9.9-4.9.16
4.9.17
18/09/2024
MC4WP <= 4.9.9 – Missing Authorization via listen
The MC4WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'listen' function in versions up to, and including, 4.9.9. This makes it possible for unauthenticated attackers to preview…
*-4.9.9
4.9.10
27/12/2023
MC4WP: Mailchimp for WordPress <= 4.8.6 – Authenticated (Admin+) Stored Cross-Site Scripting
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-4.8.6
4.8.7
02/03/2022
MC4WP: Mailchimp for WordPress < 4.8.7 – Cross-Site Scripting
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form field in versions up to, and including, 4.8.6 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 4.8.7)
4.8.7
02/03/2022
MC4WP: Mailchimp for WordPress <= 4.8.4 – Open Redirect
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to arbitrarily redirect administrators via a forged…
*-4.8.4
4.8.5
01/06/2021
MC4WP: Mailchimp for WordPress <= 4.8.4 – Cross-Site Request Forgery
The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.4. This is due to missing nonce validation on the 'listen_for_actions' function. This makes it possible for unauthenticated attackers…
*-4.8.4
4.8.5
01/06/2021
MC4WP: Mailchimp for WordPress <= 4.1.6 – Reflected Cross-Site Scripting
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_query_arg() in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.1.6
4.1.7
09/11/2019
Mailchimp For WP <= 4.1.7 – Cross-Site Scripting
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
*-4.1.7
4.1.8
08/09/2017
MailChimp for WordPress <= 4.0.10 – Reflected Cross-Site Scripting
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
[*, 4.0.11)
4.0.11
13/12/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.