MC4WP: Mailchimp for WordPress <= 4.11.1 - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion
MC4WP: Mailchimp for WordPress
Minimum safe version
4.12.0
Update to 4.12.0 or later to address 17 fixable vulnerabilities
WordPress MC4WP Plugin <= 4.9.16 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-8850
WordPress MC4WP Plugin <= 4.9.9 is vulnerable to Broken Access Control
MailChimp for WordPress <= 4.1.6 - Authenticated Cross-Site Scripting (XSS)
MC4WP: Mailchimp for WordPress < 4.8.5 - Unauthorised Actions via CSRF
MC4WP: Mailchimp for WordPress < 4.8.5 - Authenticated Arbitrary Redirect
MC4WP < 4.8.7 - Admin+ Stored Cross-Site Scripting
MC4WP: Mailchimp for WordPress <= 4.1.6 - Reflected Cross-Site Scripting
MC4WP: Mailchimp for WordPress <= 4.8.4 - Open Redirect
MC4WP: Mailchimp for WordPress <= 4.8.4 - Cross-Site Request Forgery
MC4WP: Mailchimp for WordPress < 4.8.7 - Cross-Site Scripting
WordPress MailChimp Plugin <= 4.0.10 - Cross Site Scripting
CVE-2021-36833
WordPress MC4WP plugin <= 4.8.4 - Authenticated Arbitrary Redirect vulnerability
WordPress MC4WP plugin <= 4.8.4 - Unauthorised Actions via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2016-10871
CVE-2017-18577