ZeroHour

CVE-2026-84753

moderate

Unauthenticated PHP Object Injection in Mail Mint WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-84753 is a critical (CVSS 9.8) unauthenticated PHP object injection flaw — insecure deserialization of untrusted data (CWE-502) — in Mail Mint, a WordPress email marketing and CRM automation plugin. An unauthenticated remote attacker can supply crafted serialized input that the plugin deserializes without validation, injecting attacker-controlled PHP objects into the application. Depending on the object classes available in the affected WordPress environment, this can lead to high-impact outcomes such as remote code execution, unauthorized data access, or data tampering, consistent with the high confidentiality, integrity, and impact scores. Any WordPress site running Mail Mint version 1.31.0 or earlier is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so it is not currently known to be exploited in the wild.

What to do: Update Mail Mint to the latest patched release (anything newer than 1.31.0; the fixed version is not specified in the available data, so check the plugin's changelog on WordPress.org). Sites that cannot update immediately should consider temporarily deactivating the plugin or limiting unauthenticated access to it, and defenders should monitor for a public PoC or KEV addition given the critical rating.

Affected
WPFunnels Mail Mint (WordPress email marketing / CRM automation plugin)<= 1.31.0
Estimated exposure
moderateLikely tens of thousands of WordPress sites (plugin active installs reported in the low tens of thousands) — Estimated from the plugin's publicly reported WordPress.org active-install count, which has been in the tens of thousands; the exact current figure was not included in the provided data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.