Impact
The Mail Mint plugin for WordPress versions 1.31.0 and earlier suffers a broken access control flaw that does not require authentication. An attacker can send a crafted web request to the plugin’s administrative endpoints and perform privileged actions such as changing configuration settings or altering stored data. The weakness, identified as CWE‑862, permits an unauthenticated user to obtain or modify information that should be restricted to authorized administrators. No additional privileges, such as operating system access, are required for exploitation.
Affected Systems
This vulnerability is limited to the Mail Mint plugin component of the WPFunnels product line on WordPress installations running version 1.31.0 or older. No impact on the core WordPress system or other plugins is recorded in the available data.
Risk and Exploitability
With a CVSS score of 6.5, the flaw is considered moderate severity. The public exploitation probability is currently unknown due to an unavailable EPSS score, and it is not listed in CISA’s KEV catalog. Because authentication is not required, the likely attack vector is a simple web‑based request to the plugin’s administrative URLs, without the need for credentials or other prerequisites.
OpenCVE Enrichment