CVE-2026-27349: WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability
Published May 21, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data.
This issue affects Mail Mint: from n/a through 1.19.5.
Affected Software
1 affected component
WPFunnels Team Mail Mint (WordPress plugin)<=1.19.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mail Mint Pluginto a version that resolves this vulnerability.Fixed in 1.20.0
Event History
May 21, 2026
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27349?
The severity of CVE-2026-27349 is medium with a CVSS score of 4.3.
2
What does CVE-2026-27349 affect?
CVE-2026-27349 affects the WordPress Mail Mint plugin versions up to 1.19.5.
3
How do I fix CVE-2026-27349?
To fix CVE-2026-27349, update the WordPress Mail Mint plugin to version 1.20.0 or later.
4
What type of vulnerability is CVE-2026-27349?
CVE-2026-27349 is a Sensitive Data Exposure vulnerability.
5
What can be leaked due to CVE-2026-27349?
CVE-2026-27349 allows the retrieval of embedded sensitive data.