PT-2025-45561 · WordPress · Mail Mint

Published

2025-11-08

·

Updated

2025-11-13

·

CVE-2025-11967

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mail Mint plugin for WordPress versions prior to 1.18.11
Description The Mail Mint plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation within the process contact attribute import function. This allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to the server, potentially leading to remote code execution.
Recommendations Update the Mail Mint plugin to version 1.18.11 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11967

Affected Products

Mail Mint