PT-2026-22868 · WordPress · Mail Mint
Published
2026-03-04
·
Updated
2026-03-16
·
CVE-2026-2025
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mail Mint WordPress plugin versions prior to 1.19.5
Description
The Mail Mint WordPress plugin does not have proper authorization for one of its REST API endpoints. This allows unauthenticated users to access and retrieve the email addresses of users on the WordPress blog. The affected API endpoint allows unauthorized access to user data. The vulnerable parameter is not specified.
Recommendations
Update the Mail Mint WordPress plugin to version 1.19.5 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail Mint