The Mail Mint plugin for WordPress (versions up to and including 1.31.0) contains a PHP Object Injection vulnerability via deserialization of untrusted input in the 'handle_form_submission' function. Unauthenticated attackers can exploit this flaw to inject a PHP Object. The presence of a POP (Property-Oriented Programming) chain further allows attackers to achieve remote code execution on the server. The vulnerability affects all versions through 1.31.0, with only a partial patch applied in version 1.23.1. The affected plugin provides email marketing, newsletter, email automation, and WooCommerce email functionality for WordPress sites. The vulnerability was disclosed via NVD and corroborated by Wordfence threat intelligence.