{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/the-mail-mint/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themailmint:the_mail_mint:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-10196"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Mail Mint – Email Marketing, Newsletter, Email Automation \u0026 WooCommerce Emails (\u003c= 1.31.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","rce","deserialization"],"_cs_type":"advisory","_cs_vendors":["The Mail Mint"],"content_html":"\u003cp\u003eThe Mail Mint plugin for WordPress, a tool for email marketing and automation, contains a critical PHP Object Injection vulnerability (CVE-2026-10196) affecting all versions up to and including 1.31.0. The vulnerability resides in the handle_form_submission function, which performs unsafe deserialization of untrusted user input.\u003c/p\u003e\n\u003cp\u003eBy injecting a malicious serialized PHP object, an unauthenticated remote attacker can leverage existing POP (Property Oriented Programming) chains within the application's codebase to achieve remote code execution. Although a partial fix was introduced in version 1.23.1, the vulnerability remained exploitable in subsequent releases up to 1.31.0. This flaw poses a high risk, as it allows attackers to gain unauthorized control over the underlying web server, potentially leading to full site compromise, exfiltration of sensitive email marketing data, and persistence.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution on the web server hosting the WordPress instance. This could result in total compromise of the affected WordPress site, unauthorized access to subscriber email lists, and potential lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update The Mail Mint WordPress plugin to the latest available version (beyond 1.31.0) to remediate CVE-2026-10196.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious HTTP POST requests directed at endpoints responsible for form submissions if the site was running vulnerable versions.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected child processes spawned by the web server process (e.g., www-data or nginx) originating from the WordPress installation directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T13:31:22Z","date_published":"2026-09-05T13:31:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mail-mint-rce/","summary":"The Mail Mint WordPress plugin versions 1.31.0 and earlier are vulnerable to unauthenticated remote code execution via a PHP Object Injection flaw in the handle_form_submission function.","title":"PHP Object Injection Vulnerability in The Mail Mint WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-mail-mint-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - The Mail Mint","version":"https://jsonfeed.org/version/1.1"}