Impact
The vulnerability is an unauthenticated PHP Object Injection in the Mail Mint plugin that allows an attacker to execute arbitrary code on the underlying server. This breach can compromise the confidentiality, integrity, and availability of the WordPress installation and any data or services the site hosts.
Affected Systems
WordPress sites that have the WPFunnels:Mail Mint plugin installed in versions 1.31.0 or earlier are affected. The vulnerability persists regardless of the WordPress core version or hosting environment.
Risk and Exploitability
The CVSS base score of 9.8 categorizes this flaw as critical. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves sending a crafted request to the plugin’s endpoint without requiring authentication, enabling an attacker to inject objects and trigger code execution. The risk is therefore high, given the potential for full system compromise.
OpenCVE Enrichment