CVE-2026-19800
Deferred Deferred - Pending Action

SQL Injection in Mail Mint WordPress Plugin

Vulnerability report for CVE-2026-19800, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The $wpdb->prepare() call does not protect against this injection because the attacker-controlled $contact_filter_query fragment is concatenated into the SQL format string before prepare() executes β€” prepare() only processes %s/%d placeholders and cannot sanitize content already embedded in the format string. REST API JSON bodies are parsed from php://input and bypass WordPress's wp_magic_quotes(), meaning double-quote characters in status array values reach the SQL sink unescaped. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required 'mint_read_contacts' capability is a plugin-specific capability not assigned to any default WordPress role; it must be explicitly granted by an administrator, making this effectively an Administrator+ vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mail_mint email_marketing_newsletter_email_automation_&_woocommerce_emails to 1.31.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL Injection flaw in the Mail Mint WordPress plugin. It allows authenticated attackers with administrator-level access to inject malicious SQL queries via the 'status' parameter. The issue occurs because user input is improperly escaped and concatenated into SQL queries before proper sanitization, enabling attackers to extract sensitive database information.

Detection Guidance

This vulnerability requires authenticated access with administrator-level privileges or higher. Check WordPress user roles for the 'mint_read_contacts' capability. Inspect plugin versions for Mail Mint up to 1.31.0. Monitor database queries for unusual SQL patterns or unauthorized data extraction attempts.

Impact Analysis

If you use the affected Mail Mint plugin versions, an attacker with admin access could steal sensitive data from your WordPress database, such as user credentials, emails, or other confidential information. This could lead to further attacks or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and security. Organizations using the plugin may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update the Mail Mint plugin to the latest version beyond 1.31.0 immediately. Remove or restrict administrator-level access for users not explicitly requiring it. Review and audit user roles with the 'mint_read_contacts' capability. Implement additional database logging to detect suspicious SQL queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19800. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart