CVE-2021-36833: WordPress MC4WP plugin <= 4.8.6 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36833?
The severity of CVE-2021-36833 is considered high due to the potential for authenticated users to exploit stored Cross-Site Scripting (XSS).
How do I fix CVE-2021-36833?
To fix CVE-2021-36833, update the Mailchimp for WordPress plugin to version 4.8.7 or later immediately.
Who is affected by CVE-2021-36833?
CVE-2021-36833 affects users of the Mailchimp for WordPress plugin version 4.8.6 and earlier who have admin or higher user role access.
What kind of attack does CVE-2021-36833 enable?
CVE-2021-36833 enables authenticated stored Cross-Site Scripting (XSS) attacks that can lead to unauthorized actions on behalf of affected users.
Is there any workaround for CVE-2021-36833?
There are no effective workarounds for CVE-2021-36833; updating the plugin is the only recommended solution.