Junglewise Threat Intelligence

CVE-2026-15052: WordPress MailChimp Subscribe Form stored XSS in form field values

CVE-2026-15052 · Severity: high · CVSS 7.2 · Published 2026-08-01

Executive brief

A popular WordPress plugin used for creating MailChimp subscription forms and pop-ups contains a security flaw that allows attackers to inject malicious scripts into the website. This could allow an unauthorized person to hijack user sessions, redirect visitors to dangerous websites, or deface the site. The issue affects all versions of the plugin up to 4.3.3.

Technical details

The vulnerability is classified as Stored Cross-Site Scripting (XSS) within the MailChimp Subscribe Form plugin for WordPress. It stems from a failure to properly sanitize and escape user-supplied data within form field values before storing them in the database and rendering them on the page. An unauthenticated attacker can exploit this by submitting a form containing malicious JavaScript. When an administrative user or site visitor views the page where this data is displayed, the script executes in their browser context. This can lead to session theft or unauthorized actions performed on behalf of the victim. The issue is present in versions up to 4.3.3 and was addressed in subsequent updates.

Affected products

  • umarbajwa MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder up to, and including, 4.3.3

Timeline

  • 2026-08-01: disclosed: CVE published to NVD

References