CVE-2026-84755: WordPress Mail Mint plugin <= 1.31.0 - Broken Access Control vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
Affected Software
1 affected component
WordPress Mail Mint plugin<=1.31.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mail Mint pluginto a version that resolves this vulnerability.Fixed in 1.31.1
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
What versions are affected?
Mail Mint versions 1.31.0 and earlier are affected. The provided information does not identify a fixed version.
3
What is the likely impact?
The CVSS vector indicates low confidentiality and integrity impact, with no availability impact. Successful exploitation may expose information or allow unauthorized modification, but the provided data does not specify the affected functionality.