<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Mail Mint – Email Marketing, Newsletter, Email Automation &amp; WooCommerce Emails (&lt;= 1.31.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-mail-mint--email-marketing-newsletter-email-automation--woocommerce-emails--1.31.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 13:31:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-mail-mint--email-marketing-newsletter-email-automation--woocommerce-emails--1.31.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection Vulnerability in The Mail Mint WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-mail-mint-rce/</link><pubDate>Sat, 05 Sep 2026 13:31:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mail-mint-rce/</guid><description>The Mail Mint WordPress plugin versions 1.31.0 and earlier are vulnerable to unauthenticated remote code execution via a PHP Object Injection flaw in the handle_form_submission function.</description><content:encoded><![CDATA[<p>The Mail Mint plugin for WordPress, a tool for email marketing and automation, contains a critical PHP Object Injection vulnerability (CVE-2026-10196) affecting all versions up to and including 1.31.0. The vulnerability resides in the handle_form_submission function, which performs unsafe deserialization of untrusted user input.</p>
<p>By injecting a malicious serialized PHP object, an unauthenticated remote attacker can leverage existing POP (Property Oriented Programming) chains within the application's codebase to achieve remote code execution. Although a partial fix was introduced in version 1.23.1, the vulnerability remained exploitable in subsequent releases up to 1.31.0. This flaw poses a high risk, as it allows attackers to gain unauthorized control over the underlying web server, potentially leading to full site compromise, exfiltration of sensitive email marketing data, and persistence.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthenticated remote code execution on the web server hosting the WordPress instance. This could result in total compromise of the affected WordPress site, unauthorized access to subscriber email lists, and potential lateral movement within the hosting environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update The Mail Mint WordPress plugin to the latest available version (beyond 1.31.0) to remediate CVE-2026-10196.</li>
<li>Audit web server logs for suspicious HTTP POST requests directed at endpoints responsible for form submissions if the site was running vulnerable versions.</li>
<li>Monitor for unexpected child processes spawned by the web server process (e.g., www-data or nginx) originating from the WordPress installation directory.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>rce</category><category>deserialization</category></item></channel></rss>