SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-10196

CRITICAL · CVSS 9.8 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Mail Mint plugin for WordPress is vulnerable to PHP Object Injection due to improper handling of untrusted input in the 'handle_form_submission' function, affecting all versions up to 1.31.0. This flaw allows unauthenticated attackers to inject malicious PHP objects, potentially leading to remote code execution on the server. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-10196
Severity
CRITICAL
CVSS
9.8
EPSS
0.63%
WordPress

Original NVD Description

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1.