PT-2026-86406 · WordPress · Mail Mint

·

CVE-2026-10196

·

Published

2026-09-05

·

Updated

2026-09-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails versions prior to 1.31.1
Description This issue involves PHP Object Injection caused by the deserialization of untrusted input within the handle form submission() function. This allows unauthenticated attackers to inject a PHP Object, which, combined with a POP chain (a sequence of gadgets used to execute arbitrary code), enables remote code execution on the server.
Recommendations Update the plugin to a version later than 1.31.0. As a temporary mitigation, restrict access to the handle form submission() function.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10196

Affected Products

Mail Mint