CVE-2016-10871: XSS
Published Aug 13, 2019
·Updated
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
Affected Software
2 affected components
ibericode Mailchimp Wordpress<4.0.11
ibericode Mailchimp For Wordpress Wordpress<4.0.11
Event History
Aug 13, 2019
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10871?
CVE-2016-10871 is considered a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2016-10871?
To mitigate CVE-2016-10871, update the mailchimp-for-wp plugin to version 4.0.11 or later.
3
What impact does CVE-2016-10871 have on my WordPress site?
CVE-2016-10871 can allow attackers to execute arbitrary JavaScript code in the context of the user's browser, compromising user data.
4
Who is affected by CVE-2016-10871?
Users of the mailchimp-for-wp plugin prior to version 4.0.11 on WordPress are affected by CVE-2016-10871.
5
What is the nature of the vulnerability in CVE-2016-10871?
CVE-2016-10871 is a Cross-Site Scripting (XSS) vulnerability that occurs on the integration settings page of the mailchimp-for-wp plugin.