CVE-2026-23541: WordPress Mail Mint plugin <= 1.19.4 - Broken Access Control vulnerability
Published Feb 19, 2026
·Updated
Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4.
Affected Software
1 affected component
wordpress/mail-mint<=1.19.4
Event History
Feb 19, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-23541?
CVE-2026-23541 is classified as a critical vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2026-23541?
To fix CVE-2026-23541, update the Mail Mint plugin to version 1.19.5 or later.
3
What impact does CVE-2026-23541 have on WordPress websites?
CVE-2026-23541 allows users to access functionalities that lack proper authorization, posing risks to website security and data integrity.
4
Which versions of Mail Mint are affected by CVE-2026-23541?
CVE-2026-23541 affects Mail Mint versions up to and including 1.19.4.
5
Is there a workaround for CVE-2026-23541 if I cannot update immediately?
If an immediate update is not possible, consider temporarily disabling the Mail Mint plugin to mitigate the risk associated with CVE-2026-23541.