A critical unauthenticated PHP Object Injection vulnerability has been identified in the Mail Mint WordPress plugin affecting versions 1.31.0 and below. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other serious impacts depending on available POP chains. The flaw is tracked as CVE-2026-84753 and has been documented by both the NVD and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous for sites running affected versions. Users are advised to update to a patched version of the Mail Mint plugin immediately. The vulnerability is classified with a high severity rating.