Junglewise Threat Intelligence

CVE-2026-87917: MC4WP: Mailchimp for WordPress reflected cross-site scripting

CVE-2026-87917 · Severity: medium · CVSS 6.1 · Published 2026-09-19

Executive brief

The MC4WP: Mailchimp for WordPress plugin, used by websites to manage email subscription forms, is vulnerable to reflected cross-site scripting attacks. An attacker can craft a malicious link that, when clicked by a user, injects malicious code into the webpage and executes it in the victim's browser, potentially stealing credentials or session information without requiring authentication.

Technical details

The vulnerability exists in the 'data' dynamic content tag handler due to insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary JavaScript through URL parameters that gets reflected in the page response without proper escaping. This reflected XSS requires user interaction (clicking a crafted link) but can compromise session tokens or sensitive data.

Affected products

  • MC4WP Mailchimp for WordPress up to and including 4.14.0

Timeline

  • 2026-09-19: disclosed

References

Related threats