Executive brief
Mail Mint is a WordPress plugin used for email management and marketing campaigns. An unauthenticated attacker can inject malicious PHP objects into the plugin to execute arbitrary code on the website server, potentially compromising customer data, stealing credentials, or deploying ransomware with no authentication required.
Technical details
This vulnerability is a PHP Object Injection flaw in Mail Mint plugin versions up to 1.31.0. The vulnerable code allows unauthenticated attackers to manipulate how the application deserializes user-supplied data, enabling arbitrary code execution on the server. The attack requires only network access (no authentication or user interaction needed) and can be exploited remotely. Successful exploitation allows attackers to achieve remote code execution with server privileges. The vulnerability was patched in version 1.31.1.
Affected products
- WPFunnels Team Mail Mint <= 1.31.0
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Patch version 1.31.1 released
- 2026-04-24: other: Vulnerability reported to developer