Executive brief
Mail Mint is a WordPress plugin that handles email marketing and funnel management for online stores and marketing campaigns. The plugin contains a broken access control flaw that allows unauthenticated attackers to access sensitive pages and perform unauthorized actions, including viewing data they should not have access to. This could expose customer information, email lists, and marketing campaign data to malicious actors.
Technical details
The vulnerability is a broken access control issue in Mail Mint versions up to 1.31.0 that fails to properly validate user permissions before granting access to sensitive functionality. The flaw is exploitable without authentication, meaning an attacker does not need valid WordPress credentials to trigger the vulnerability. By directly accessing protected endpoints or performing unauthorized actions through the plugin, attackers can bypass authorization checks and access or modify data that should be restricted. The vulnerability has been patched in version 1.31.1 and later.
Affected products
- WPFunnels Mail Mint <= 1.31.0
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Version 1.31.1 and later
- 2026-09-03: kev added
- 2026-06-21: other: Reported to vendor by WiniS