← Terug naar overzicht

A critical unauthenticated PHP Object Injection vulnerability has been identified in the Mail Mint WordPress plugin affecting versions 1.31.0 and below. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other serious impacts depending on available POP chains. The flaw is tracked as CVE-2026-84753 and has been documented by both the NVD and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous for sites running affected versions. Users are advised to update to a patched version of the Mail Mint plugin immediately. The vulnerability is classified with a high severity rating.

Affected products

  • Mail Mint WordPress Plugin <= 1.31.0

Related CVE's

  • CVE-2026-84753

Categories

  • Enterprise Applications
  • Web Technologies