cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formailchimp-subscribe-sm mailchimp-subscribe-sm

Direction: ascending
Jun 06, 2024

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder # CVE-2023-33328

CVE, Research URL

CVE-2023-33328

Date
May 28, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.
Affected versions
max 1.2.
Status
vulnerable

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder # CVE-2023-32517

CVE, Research URL

CVE-2023-32517

Date
Dec 29, 2023
Research Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.This issue affects MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder: from n/a through 4.0.9.3.
Affected versions
max 4.0.9.4.
Status
vulnerable

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder # 8d47bb64d05cfe1cfbaf909388f1eca7797ab7d2

Date
May 26, 2015
Research Description
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder [mailchimp-subscribe-sm] < 1.2 WordPress MailChimp Subscribe Forms Plugin 1.1 - Remote Code Execution MailChimp Subscribe Forms plugin is prone to a remote code execution vulnerability via "email" field. Upgrade the plugin.
Affected versions
max 1.2.
Status
vulnerable
Aug 13, 2024

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder # CVE-2024-43211

CVE, Research URL

CVE-2024-43211

Date
Nov 01, 2024
Research Description
Cross Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Forms allows Stored XSS.This issue affects MailChimp Subscribe Forms: from n/a through 4.0.9.8.
Affected versions
max 4.0.9.9.
Status
vulnerable
Jan 19, 2025

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder # CVE-2025-22727

CVE, Research URL

CVE-2025-22727

Date
Jan 21, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChimp Subscribe Forms allows Stored XSS. This issue affects MailChimp Subscribe Forms : from n/a through 4.1.
Affected versions
max 4.2.
Status
vulnerable