WORDPRESS · SEPTEMBER 2026 · EARLY WARNING

Mail Mint WordPress Plugin Vulnerable to PHP Object Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
mail mint (wordpress)
Patched version
1.23.1
CVE-2026-10196

The Mail Mint WordPress plugin, versions up to and including 1.31.0, is reportedly vulnerable to PHP Object Injection. This vulnerability allows unauthenticated attackers to execute code on the server.

What happened

The Mail Mint, Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is under investigation for a critical vulnerability. The plugin, in all versions up to and including 1.31.0, appears to be susceptible to PHP Object Injection via deserialization of untrusted input in the 'handle_form_submission' function. This vulnerability, tracked as CVE-2026-10196, could allow unauthenticated attackers to inject a PHP Object. The presence of a POP chain further enables attackers to execute code on the server.

The vulnerability has a CVSS score of 9.8, indicating a critical severity level. It is recommended to upgrade to version 1.23.1 or higher to mitigate the risk. Additionally, reviewing server logs for any suspicious activity is advised.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mail mint is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the Mail Mint plugin version 1.31.0 or lower, you are potentially affected.

What should I do right now?

Upgrade to version 1.23.1 or higher and review your server logs for any suspicious activity.

Is this vulnerability being exploited in the wild?

There is no confirmed evidence of this vulnerability being exploited in the wild at this time.

Where can I find more information about this vulnerability?

Consult the primary sources provided, including the NVD entry for CVE-2026-10196.

Sources

Join the 0Day waitlist →

← Back to all threats