PHP Object Injection Vulnerability in Mail Mint Email Marketing Plugin for WordPress
CVE-2026-10196
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-10196?
The Mail Mint plugin for WordPress is susceptible to PHP Object Injection due to improper handling of user inputs in the 'handle_form_submission' function. This vulnerability permits unauthenticated attackers to manipulate the deserialization process, enabling them to inject malicious PHP objects. Furthermore, the presence of a chain of PHP Object Patterns (POP) can result in code execution on the server side, making this issue quite severe for users relying on this email marketing solution.
Affected Version(s)
Mail Mint β Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 1.31.0