Impact
The Mail Mint plugin accepts user-provided data that is incorporated directly into an SQL query without adequate sanitization, creating a classic SQL Injection (CWE-89) flaw. An attacker who can influence the input fields can inject arbitrary SQL code, potentially reading, modifying, or deleting database contents and compromising user data or site functionality.
Affected Systems
The vulnerability affects the WPFunnels Mail Mint WordPress plugin in all versions up to and including 1.18.5. Administrators should verify that their site is running this plugin version or earlier and update accordingly to remove the issue.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, yet the EPSS score of less than 1% suggests a very low current exploitation probability. The plugin is not listed in CISA's KEV catalog, so there have been no confirmed public exploits recorded. The attack vector is inferred to be remote, via the plugin’s exposed form fields that are delivered through a web browser. Exploitation would typically require an attacker to be able to submit crafted input to the plugin’s endpoint.
OpenCVE Enrichment
EUVD