CRITICAL
9.8 CVE-2026-10196 Published 5 Sept 2026
WordPress Mail Mint Plugin PHP Object Injection
Worried this affects one of your servers?
The Mail Mint plugin for WordPress is vulnerable to PHP Object Injection in versions up to 1.31.0.
This allows unauthenticated attackers to inject a PHP Object, and with the presence of a POP chain, execute code on the server.
Impact: The vulnerability was partially patched in version 1.23.1.
Reference: CVE-2026-10196 on NVD
← Back to Security News