Junglewise Threat Intelligence

CVE-2026-27349: WPFunnels Team Mail Mint sensitive data exposure

CVE-2026-27349 · Severity: medium · CVSS 4.3 · Published 2026-05-21

Technologies: WPFunnels Team Mail Mint. Vendors: WPFunnels Team.

Executive brief

Mail Mint is a WordPress plugin used for email marketing and automation. A security vulnerability in this plugin allows logged-in users with low-level permissions to access sensitive system information that should be restricted. This could lead to the exposure of internal configuration details, potentially aiding an attacker in planning further attacks against the website.

Technical details

A sensitive data exposure vulnerability (CWE-497) exists in the WPFunnels Team Mail Mint plugin for WordPress through version 1.19.5. The flaw allows an authenticated attacker, typically with Subscriber-level privileges, to access sensitive system information that is improperly exposed to an unauthorized control sphere. The vulnerability stems from insufficient access controls on certain data endpoints or embedded system details. An attacker can exploit this over the network without user interaction to gain insights into the system's internal state or configuration. The issue is addressed in version 1.20.0.

Affected products

  • WPFunnels Team Mail Mint up to 1.19.5

Timeline

  • 2025-11-29: other: Reported by researcher Que Thanh Tuan
  • 2026-05-21: patched: Version 1.20.0 released to address the issue
  • 2026-05-21: disclosed: Vulnerability published by Patchstack and NVD

References

Related threats