CVE-2025-59570: WordPress Mail Mint Plugin <= 1.18.6 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint allows SQL Injection. This issue affects Mail Mint: from n/a through 1.18.6.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint mail-mint allows SQL Injection.This issue affects Mail Mint: from n/a through <= 1.18.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59570?
CVE-2025-59570 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-59570?
To fix CVE-2025-59570, you should update WPFunnels Mail Mint or WordPress Mail Mint Plugin to version 1.18.7 or later.
What types of systems are affected by CVE-2025-59570?
CVE-2025-59570 affects versions of WPFunnels Mail Mint and WordPress Mail Mint Plugin up to and including 1.18.6.
What are the risks associated with CVE-2025-59570?
The risks associated with CVE-2025-59570 include unauthorized access to the database, data manipulation, and exposure of sensitive information.
How can CVE-2025-59570 be exploited?
CVE-2025-59570 can be exploited through specially crafted SQL commands that are injected into input fields of the affected applications.