CVE-2026-87917: MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dynamic Content Tag
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need to authenticate. Exploitation requires persuading a user to perform an action such as clicking a crafted link.
Which installations are affected?
MC4WP: Mailchimp for WordPress versions through 4.14.0 are affected. The provided information does not identify a configuration prerequisite.
What is the likely impact if exploitation succeeds?
Arbitrary script can execute in the affected page in the context of the user who follows the attacker-controlled link. The listed impact includes low confidentiality and integrity impact, with no availability impact.