Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84753: Mail Mint plugin can let attackers run code

CVE-2026-84753 · published today
Summary

The Mail Mint add‑on for WordPress (versions up to 1.31.0) can be tricked into executing unwanted commands without any login. This could let a stranger take control of your site or steal data. Update the plugin to the latest version or uninstall it if you don't need it.

What to do
  • Update wpfunnels mail mint to version 1.31.1.
Affected software
VendorProductAffected versions
wpfunnels mail mint <= 1.31.0
Fix: upgrade to 1.31.1
Original advisory text
WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-84753 · MITRE
Monitor software like this
Free during beta