VYPR
Medium severity6.1NVD Advisory· Published Oct 26, 2024· Updated Apr 15, 2026

CVE-2024-8870

CVE-2024-8870

Description

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Forms for Mailchimp by Optin Cat plugin versions up to 2.5.7 due to improper escaping in add_query_arg.

Vulnerability

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in all versions up to, and including, 2.5.7. The vulnerability exists in the includes/eoi-subscribers.php file [1] because add_query_arg is used without appropriate escaping on the URL [1][2]. This allows unauthenticated attackers to inject arbitrary web scripts.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious link that includes a payload as a query parameter. The attacker then tricks a user into clicking the link, for example via social engineering or by placing the link on a controlled site. The unescaped URL parameters are reflected back in the page response, causing the injected script to execute in the victim's browser. The vulnerability is reflected and requires user interaction (clicking the link) [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session on the affected WordPress site. This can lead to information disclosure (data theft, session hijacking), and other actions that can be performed by scripts in the browser. The attacker does not need prior authentication or high privileges [1].

Mitigation

The vendor has released a fix in changeset 3198558 [2]. Users should update the plugin to version 2.5.8 or later. As of the publication date (2024-10-26), no specific workaround is documented, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

1

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.