What the vulnerability does
01Description
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
Explanation of Vulnerability in Simple Terms
MC4WP: Mailchimp for WordPress versions up to 4.8.6 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with high privileges can inject malicious scripts that execute in the browsers of other site visitors. The vulnerability requires user interaction to trigger and affects the plugin's admin interface. Site owners should update to a version newer than 4.8.6.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view affected plugin pages.
Potential impact on your site
Admins or other high-privilege users could be compromised if they visit a page containing injected malicious code.
Conditions required to exploit
Attacker must have high-level admin privileges and a victim must visit the affected admin page.
Key dates
External resources
Related vulnerabilities