CVE-2026-87917
Received Received - Intake

Reflected Cross-Site Scripting in MC4WP Mailchimp for WordPress

Vulnerability report for CVE-2026-87917, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: Wordfence

Description

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mailchimp mc4wp to 4.14.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MC4WP: Mailchimp for WordPress plugin has a reflected cross-site scripting vulnerability in its Dynamic Content Tag feature. This flaw allows unauthenticated attackers to inject malicious scripts into web pages by tricking users into clicking a link. The issue stems from insufficient input sanitization and output escaping in versions up to 4.14.0.

Impact Analysis

This vulnerability could allow attackers to steal user sessions, redirect users to malicious sites, or perform actions on their behalf. Users might unknowingly execute harmful scripts if they click a crafted link, potentially compromising their accounts or data.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face compliance breaches if user data is exposed due to this flaw.

Mitigation Strategies

Update the MC4WP: Mailchimp for WordPress plugin to the latest version, which is beyond 4.14.0. Remove any unused Dynamic Content Tags and review existing tags for suspicious content. Implement input sanitization and output escaping for all user-supplied data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87917. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart