Sensitive Data Exposure in Mail Mint by WPFunnels
CVE-2025-47541

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 May 2025

What is CVE-2025-47541?

A sensitive data exposure vulnerability in WPFunnels Mail Mint could facilitate the retrieval of embedded sensitive information. This issue impacts versions from n/a up to 1.17.7, potentially allowing unauthorized access to user data, which could lead to serious privacy concerns. Organizations utilizing this plugin are advised to assess their systems for potential leaks and apply necessary security measures to safeguard sensitive information.

Affected Version(s)

Mail Mint <= 1.17.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson (Patchstack Alliance)
.