SQL Injection Vulnerability in Mail Mint Email Marketing Plugin for WordPress
CVE-2026-19800
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-19800?
The Mail Mint plugin for WordPress is susceptible to an SQL Injection vulnerability through the 'status' parameter in all versions prior to 1.31.0. This arises due to inadequate parameter escaping and insufficient preparation within the SQL query. The vulnerability allows authenticated administrators to inject malicious SQL commands by exploiting the concatenation of user input into the SQL query, circumventing SQL sanitization mechanisms. Notably, the use of REST API JSON bodies bypasses WordPress's security features, enabling the passage of unsafe input directly to SQL execution. Attackers with the 'mint_read_contacts' capability, which is not assigned by default and requires explicit permission from an administrator, can exploit this vulnerability to extract sensitive information from the database, highlighting the need for urgent mitigation efforts.
Affected Version(s)
Mail Mint β Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 1.31.0