CVE-2026-84753: WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
Affected Software
1 affected component
wordpress/mail-mint<=1.31.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mail Mint pluginto a version that resolves this vulnerability.Fixed in 1.31.1
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
2
What is the potential security impact if the issue is exploited?
The vulnerability is rated critical with a CVSS score of 9.8. It is assessed as having high impact on confidentiality, integrity, and availability, with scope unchanged.