WordPress Forms for Mailchimp by Optin Cat Plugin <= 2.5.4 is vulnerable to Cross Site Scripting (XSS)
Description
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin <= 2.5.4 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Optin Cat's Mailchimp plugin ≤2.5.4 via editor-level form creation, allowing malicious script injection into Mailchimp forms.
Vulnerability
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability exists in Fatcat Apps’ Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin versions <= 2.5.4. The issue allows users with editor-level access or higher to inject arbitrary JavaScript into Mailchimp forms via the form creation interface, which is then stored and executed when other users (including administrators) view the affected form [1].
Exploitation
An attacker must have an editor, author, or administrator role on the WordPress site. The attacker crafts a Mailchimp form containing malicious JavaScript in one of the input fields (e.g., form title, description, or custom HTML fields). Once the form is saved, the payload is stored in the database. When any user (including site visitors or other admins) views the page or widget displaying that form, the injected script executes in their browser session [1]. No additional user interaction beyond loading the page is required.
Impact
Successful exploitation leads to stored XSS, enabling the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can result in session hijacking, credential theft, defacement, or redirection to malicious sites. The attacker does not gain direct server-level control but can compromise administrative accounts if an admin views the poisoned form [1].
Mitigation
The vulnerability is fixed in version 2.6.2 of the plugin, released on 2026-04-11 [1]. Users are strongly advised to update to version 2.6.2 or later. No workaround is available, and the plugin should not be used without the update. The plugin is not currently listed on CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=2.5.4
- Fatcat Apps/Forms for Mailchimp by Optin Cat – Grow Your MailChimp Listv5Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.