PHP Object Injection Vulnerability in Mail Mint Email Marketing Plugin for WordPress
CVE-2026-10196

9.8CRITICAL

What is CVE-2026-10196?

The Mail Mint plugin for WordPress is susceptible to PHP Object Injection due to improper handling of user inputs in the 'handle_form_submission' function. This vulnerability permits unauthenticated attackers to manipulate the deserialization process, enabling them to inject malicious PHP objects. Furthermore, the presence of a chain of PHP Object Patterns (POP) can result in code execution on the server side, making this issue quite severe for users relying on this email marketing solution.

Affected Version(s)

Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 1.31.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

maru
.