CVE-2026-84753
moderateUnauthenticated PHP Object Injection in Mail Mint WordPress Plugin
CVE-2026-84753 is a critical (CVSS 9.8) unauthenticated PHP object injection flaw — insecure deserialization of untrusted data (CWE-502) — in Mail Mint, a WordPress email marketing and CRM automation plugin. An unauthenticated remote attacker can supply crafted serialized input that the plugin deserializes without validation, injecting attacker-controlled PHP objects into the application. Depending on the object classes available in the affected WordPress environment, this can lead to high-impact outcomes such as remote code execution, unauthorized data access, or data tampering, consistent with the high confidentiality, integrity, and impact scores. Any WordPress site running Mail Mint version 1.31.0 or earlier is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so it is not currently known to be exploited in the wild.
What to do: Update Mail Mint to the latest patched release (anything newer than 1.31.0; the fixed version is not specified in the available data, so check the plugin's changelog on WordPress.org). Sites that cannot update immediately should consider temporarily deactivating the plugin or limiting unauthenticated access to it, and defenders should monitor for a public PoC or KEV addition given the critical rating.
| WPFunnels Mail Mint (WordPress email marketing / CRM automation plugin) | <= 1.31.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.