S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 18, 2025

CVE-2023-2518 Scanner

CVE-2023-2518 Scanner - Cross-Site Scripting vulnerability in Easy Forms for Mailchimp

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2518
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Easy Forms for Mailchimp
AFFECTED< 6.8.9SAFE ✓≥ 6.8.9
Updated Aug 22, 2026View on NVD →
Detail

The Easy Forms for Mailchimp is a popular WordPress plugin used to create and manage subscription forms for Mailchimp directly from a WordPress site. This plugin is commonly used by website administrators and digital marketers who aim to simplify the process of capturing leads and integrating them with their Mailchimp accounts. It provides users with a user-friendly interface and various customization options for the subscription forms. The plugin's purpose is to improve the efficiency of email marketing campaigns by ensuring seamless integration with Mailchimp services. Easy Forms for Mailchimp is often employed on small to medium-sized business websites that rely heavily on email marketing strategies.

The vulnerability identified in the Easy Forms for Mailchimp plugin is a Cross-Site Scripting (XSS) flaw that affects versions prior to 6.8.9. This issue arises when the plugin does not adequately sanitize and escape the `sql_error` parameter output on a page while the debug option is enabled. Such vulnerabilities can allow attackers to execute arbitrary JavaScript code in the context of an administrator's browser session. By exploiting this XSS vulnerability, attackers can effectively gain unauthorized access or manipulate web application behaviors.

The technical details of this XSS vulnerability involve improper handling of the `sql_error` parameter by the Easy Forms for Mailchimp plugin. When an administrator enables the debug option, the unsanitized `sql_error` value may be inserted directly into the page’s content, which can be manipulated to include harmful script. An attacker could craft a request that carries a malicious payload, like using SVG tags for script execution, which would be activated upon page load within the admin panel interface. The vulnerability enables arbitrary JavaScript execution, reflecting unsanitized input back to the user's browser without proper validation.

Malicious exploitation of this Cross-Site Scripting vulnerability can lead to severe security risks. Attackers might execute scripts that perform administrative actions, exfiltrate cookies, or redirect administrators to phishing pages. Consequently, they could capture session tokens, enabling unauthorized access to sensitive administrative functionalities within the WordPress website. This vulnerability jeopardizes the integrity and privacy of the website's security management if not promptly patched to restrict such script execution.

REFERENCES

Solution Advice
  • Update the Easy Forms for Mailchimp plugin to version 6.8.9 or later to patch the XSS vulnerability.
  • Review security settings and disable debugging options unless necessary for troubleshooting.
  • Implement Content Security Policy (CSP) to restrict script execution permissions.
  • Regularly audit the plugins and themes for potential security updates and patches.
  • Conduct regular security training for WordPress administrators regarding secure browsing practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-2518 Scanner - Cross-Site Scripting vulnerability in Easy Forms for Mailchimp | S4E