Impact
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin allows authenticated attackers with administrator-level access to inject arbitrary SQL fragments through the 'status' parameter. The vulnerability arises because the parameter is concatenated into an existing SQL query before the call to $wpdb->prepare(), which cannot sanitize content already embedded in the format string. The REST API accepts JSON payloads parsed from php://input, bypassing WordPress wp_magic_quotes(), allowing double‑quote characters in the status array to reach the database unescaped. The attacker can append additional SQL statements to read sensitive data from the database, which is protected by the plugin‑specific 'mint_read_contacts' capability; this capability must be explicitly granted by an administrator, making the flaw effectively an Administrator+ vulnerability.
Affected Systems
GetWPFunnels' Mail Mint plug‑in for WordPress is affected in all releases up to and including version 1.31.0. Any instance running 1.31.0 or an earlier version is vulnerable to the SQL injection described above.
Risk and Exploitability
The flaw receives a CVSS score of 4.9, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a logged‑in attacker who can exercise the REST API endpoints exposed by the plug‑in; the attacker must possess administrator privileges or any role granted the 'mint_read_contacts' capability to exploit this flaw. At the time of analysis, no public exploits have been confirmed, but the nature of the injection allows for data exfiltration and could be leveraged for further attacks if combined with other weaknesses.
OpenCVE Enrichment