SQL Injection Vulnerability in Mail Mint Email Marketing Plugin for WordPress
CVE-2026-19800

4.9MEDIUM

What is CVE-2026-19800?

The Mail Mint plugin for WordPress is susceptible to an SQL Injection vulnerability through the 'status' parameter in all versions prior to 1.31.0. This arises due to inadequate parameter escaping and insufficient preparation within the SQL query. The vulnerability allows authenticated administrators to inject malicious SQL commands by exploiting the concatenation of user input into the SQL query, circumventing SQL sanitization mechanisms. Notably, the use of REST API JSON bodies bypasses WordPress's security features, enabling the passage of unsafe input directly to SQL execution. Attackers with the 'mint_read_contacts' capability, which is not assigned by default and requires explicit permission from an administrator, can exploit this vulnerability to extract sensitive information from the database, highlighting the need for urgent mitigation efforts.

Affected Version(s)

Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 1.31.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.