CVE-2017-18577: XSS
Published Aug 22, 2019
·Updated
The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of addqueryarg.
Affected Software
2 affected components
ibericode Mailchimp Wordpress<4.1.8
ibericode Mailchimp For Wordpress Wordpress<4.1.8
Event History
Aug 22, 2019
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-18577?
CVE-2017-18577 is classified as a high-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-18577?
To fix CVE-2017-18577, update the Mailchimp for WP plugin to version 4.1.8 or later.
3
What kind of attack can CVE-2017-18577 lead to?
CVE-2017-18577 can lead to cross-site scripting (XSS) attacks that can compromise the security of a WordPress site.
4
Which versions of the Mailchimp for WP plugin are affected by CVE-2017-18577?
CVE-2017-18577 affects all versions of the Mailchimp for WP plugin prior to version 4.1.8.
5
Is CVE-2017-18577 specific to any particular WordPress setup?
CVE-2017-18577 is specifically tied to the Mailchimp for WP plugin when used in WordPress installations.