← WordPress Vulnerabilities
WordPress security by component

MC4WP: Mailchimp for

MC4WP: Mailchimp for is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Mar 11, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: mailchimp-for-wp

CVE-2026-1781: MC4WP: Mailchimp for: A security weakness

MC4WP: Mailchimp for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMar 11, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 11, 2026 CVE-2026-1781
MC4WP: Mailchimp for: A security weakness
MC4WP: Mailchimp for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Sep 21, 2024 CVE-2024-8680
MC4WP: Mailchimp for: Cross-site scripting
MC4WP: Mailchimp for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.5
Sep 19, 2024 CVE-2024-8850
MC4WP: Mailchimp for: Cross-site scripting
MC4WP: Mailchimp for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 11, 2024 CVE-2023-51682
MC4WP: A security weakness
MC4WP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
May 20, 2022 CVE-2021-36833
MC4WP: Cross-site scripting
MC4WP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 22, 2019 CVE-2017-18577
Mailchimp For Wp: Cross-site scripting
Mailchimp For Wp is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 13, 2019 CVE-2016-10871
Mailchimp For Wp: Cross-site scripting
Mailchimp For Wp is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1