Executive brief
Mail Mint, a WordPress plugin used for email marketing and WooCommerce automation, contains a security flaw that could allow an administrator to access sensitive information from the website's database. By submitting specially crafted data through the plugin's campaign settings, an attacker can bypass security checks and run unauthorized database commands. While this requires high-level access, it could lead to the exposure of customer data or other internal site information.
Technical details
A second-order SQL injection vulnerability exists in the Mail Mint plugin due to insufficient escaping and lack of query preparation. The flaw occurs because the 'recipients' parameter in a POST request to /mrm/v1/campaigns/ bypasses filter_recipients() validation; an integer cast of a malicious string (e.g., '1) OR ...') evaluates to a valid numeric ID, allowing the payload to be stored. The injection is triggered when a subsequent GET request to /mrm/v1/campaigns/{id} deserializes the data and passes the raw string through array_column() into a vulnerable SQL query. Authenticated attackers with administrator-level privileges can leverage this to append arbitrary SQL queries and extract sensitive data from the WordPress database.
Affected products
- getwpfunnels Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails up to, and including, 1.24.1
Timeline
- 2026-07-10: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/API/Controllers/Admin/CampaignController.php
- https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/API/Controllers/Admin/CampaignController.php
- https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/Database/models/ContactGroupPivotModel.php
- https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/MrmCommon.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3592458%40mail-mint&new=3592458%40mail-mint
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bf7c500e-311f-4db5-8a54-de7b02fb11dd?source=cve