Junglewise Threat Intelligence

CVE-2026-14342: getwpfunnels Mail Mint SQL injection in contact_ids

CVE-2026-14342 · Severity: medium · CVSS 4.9 · Published 2026-07-09

Executive brief

Mail Mint is a WordPress plugin used for managing email marketing campaigns and WooCommerce customer communications. A security flaw allows an authorized administrator to run unauthorized database commands. This could lead to the theft of sensitive customer information or other data stored in the website's database.

Technical details

The Mail Mint plugin for WordPress is vulnerable to time-based SQL injection due to insufficient escaping of the 'contact_ids' parameter and a lack of SQL query preparation in the ContactModel.php component. An authenticated attacker with administrator-level privileges can exploit this by sending crafted network requests to append additional SQL queries to existing ones. This vulnerability (CWE-89) allows for the extraction of sensitive data from the database using time-based blind techniques. The issue affects all versions up to and including 1.24.2; a fix was introduced in subsequent updates.

Affected products

  • getwpfunnels Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails <= 1.24.2

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References