CVE-2026-10196
Received Received - Intake

PHP Object Injection in Mail Mint WordPress Plugin

Vulnerability report for CVE-2026-10196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: Wordfence

Description

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mail_mint email_marketing_newsletter_email_automation_&_woocommerce_emails to 1.31.0 (inc)
mail_mint email_marketing_plugin to 1.31.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the Mail Mint WordPress plugin. It allows unauthenticated attackers to inject a PHP object via deserialization of untrusted input in the 'handle_form_submission' function. If a POP chain exists, attackers can execute arbitrary code on the server. The issue affects versions up to 1.31.0.

Impact Analysis

An attacker could exploit this to take control of your WordPress site, steal sensitive data, or use it as a launch point for further attacks. Since it requires no authentication, any unpatched site is at risk of compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection. A breach may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately update the Mail Mint plugin to the latest version, specifically version 1.31.1 or higher, to patch the PHP Object Injection vulnerability. If updating is not possible, consider disabling or removing the plugin until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart