PT-2026-8099 · WordPress · Mail Mint

Paolo Tresso

·

Publicado

2026-02-14

·

Atualizado

2026-02-14

·

CVE-2026-1258

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mail Mint versions prior to 1.19.3
Description The Mail Mint plugin for WordPress is susceptible to blind SQL Injection. This is due to inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. Specifically, the 'order-by', 'order-type', and 'selectedCourses' parameters in the following API endpoints are vulnerable: 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map'. An authenticated attacker with administrator-level access or higher can append additional SQL queries to existing ones.
Recommendations Update Mail Mint to version 1.19.3 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1258

Produtos afetados

Mail Mint