Mail Mint WordPress Plugin Vulnerable to PHP Object Injection
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- mail mint (wordpress)
- Patched version
- 1.23.1
The Mail Mint WordPress plugin, versions up to and including 1.31.0, is reportedly vulnerable to PHP Object Injection. This vulnerability allows unauthenticated attackers to execute code on the server.
What happened
The Mail Mint, Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is under investigation for a critical vulnerability. The plugin, in all versions up to and including 1.31.0, appears to be susceptible to PHP Object Injection via deserialization of untrusted input in the 'handle_form_submission' function. This vulnerability, tracked as CVE-2026-10196, could allow unauthenticated attackers to inject a PHP Object. The presence of a POP chain further enables attackers to execute code on the server.
The vulnerability has a CVSS score of 9.8, indicating a critical severity level. It is recommended to upgrade to version 1.23.1 or higher to mitigate the risk. Additionally, reviewing server logs for any suspicious activity is advised.
What to do about it
- Upgrade the Mail Mint plugin to version 1.23.1 or higher.
- Review server logs for any suspicious activity.
- Monitor the primary sources for updates on the vulnerability.
- Ensure that all WordPress plugins are kept up to date to prevent similar vulnerabilities.
How 0Day would have caught this
mail mint is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the Mail Mint plugin version 1.31.0 or lower, you are potentially affected.
What should I do right now?
Upgrade to version 1.23.1 or higher and review your server logs for any suspicious activity.
Is this vulnerability being exploited in the wild?
There is no confirmed evidence of this vulnerability being exploited in the wild at this time.
Where can I find more information about this vulnerability?
Consult the primary sources provided, including the NVD entry for CVE-2026-10196.