First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N-Media Nmedia MailChimp allows Stored XSS. This issue affects Nmedia MailChimp: from n/a through 5.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mailchimp | <=5.4 | |
Mailchimp | <=5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30613 is classified as a stored cross-site scripting (XSS) vulnerability, which can lead to significant security risks.
To fix CVE-2025-30613, update the Nmedia MailChimp plugin to version 5.5 or later to mitigate the XSS vulnerability.
CVE-2025-30613 affects N-Media Nmedia MailChimp and the WordPress Nmedia MailChimp plugin versions up to and including 5.4.
Attackers can exploit CVE-2025-30613 to inject malicious scripts into web pages, potentially leading to unauthorized actions on behalf of users.
If an immediate update isn't possible, it's advisable to disable the Nmedia MailChimp plugin temporarily to prevent exploitation of CVE-2025-30613.