WordPress · Mc4Wp: Mailchimp For Wordpress · CVE-2026-87917
**Name of the Vulnerable Software and Affected Versions**
MC4WP: Mailchimp for WordPress versions prior to 4.14.1
**Description**
Insufficient input sanitization and output escaping in the `data` Dynamic Content Tag allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs when an attacker tricks a user into clicking a malicious link, leading to the execution of arbitrary web scripts in the user's browser.
**Recommendations**
Update MC4WP: Mailchimp for WordPress to version 4.14.1 or later.