Impact
The Mail Mint WordPress plugin suffers from PHP Object Injection caused by deserialization of untrusted input within the handle_form_submission routine. This flaw falls under CWE-502, an improper deserialization weakness, and permits an unauthenticated attacker to inject crafted object data. When combined with a potential POP chain, the attacker can execute arbitrary code on the web server, thereby compromising confidentiality, integrity, and availability of the affected site.
Affected Systems
All releases of the Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin produced by getwpfunnels (including version 1.31.0 and earlier) are affected. The developer issued a partial patch in version 1.23.1, but the extent of remediation in later releases is not confirmed by the available data.
Risk and Exploitability
With a CVSS base score of 9.8, the flaw is classified as critical. Endpoints that expose the form submission route provide a public, unauthenticated attack vector, meaning any Internet‑connected WordPress site with the plugin can be targeted. EPSS data is not available and the issue is not yet in the CISA Known Exploited Vulnerabilities catalog, yet the high severity and open access suggest that opportunistic exploitation is likely and could lead to full compromise of the host.
OpenCVE Enrichment