cleantalk
Vulnerabilities and Security Researches

Email Marketing, Email Automation & Newsletter for WordPress & WooCommerce – Mail Mint, CVE-2026-2025

CVE, Research URL

CVE-2026-2025

Published on
Mar 04, 2026
Research Description
The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog
Affected versions
max 1.19.5.
Status
vulnerable