PT-2026-86406 · WordPress · Mail Mint
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails versions prior to 1.31.1
Description
This issue involves PHP Object Injection caused by the deserialization of untrusted input within the
handle form submission() function. This allows unauthenticated attackers to inject a PHP Object, which, combined with a POP chain (a sequence of gadgets used to execute arbitrary code), enables remote code execution on the server.Recommendations
Update the plugin to a version later than 1.31.0.
As a temporary mitigation, restrict access to the
handle form submission() function.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail Mint