Stored Cross-Site Scripting Vulnerability in Mailchimp for WordPress Plugin
CVE-2026-4561
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-4561?
The Mailchimp for WordPress plugin is exposed to a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping in the form response message post meta fields, such as 'text_subscribed' and 'text_error'. This flaw permits authenticated users with Author-level access or higher to insert arbitrary web scripts into pages. These scripts could execute whenever a user visits an affected page, thereby compromising the integrity of the website and the safety of its visitors.
Affected Version(s)
MC4WP: Mailchimp for WordPress 0 <= 4.12.0