Description
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-9693 | The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. |
References
| Link | Providers |
|---|---|
| https://wordpress.org/plugins/mailchimp-for-wp/#developers |
|
History
Tue, 27 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibericode mailchimp For Wordpress
|
|
| CPEs | cpe:2.3:a:ibericode:mailchimp_for_wordpress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ibericode mailchimp
|
Ibericode mailchimp For Wordpress
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:28:55.362Z
Reserved: 2019-08-21T00:00:00.000Z
Link: CVE-2017-18577
No data.
Status : Modified
Published: 2019-08-22T14:15:12.023
Modified: 2026-01-27T21:00:01.637
Link: CVE-2017-18577
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD