CVE-2017-18577: Ibericode Mailchimp For WordPress

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

Affected products

  • Ibericode Mailchimp For WordPress: before 4.1.8 (fixed in 4.1.8)

Published 2019-08-22. Last modified 2026-06-17.