CRITICAL 9.8 CVE-2026-10196 Published 5 Sept 2026

WordPress Mail Mint Plugin PHP Object Injection

Worried this affects one of your servers?

The Mail Mint plugin for WordPress is vulnerable to PHP Object Injection in versions up to 1.31.0.

This allows unauthenticated attackers to inject a PHP Object, and with the presence of a POP chain, execute code on the server.

Impact: The vulnerability was partially patched in version 1.23.1.

Reference: CVE-2026-10196 on NVD

← Back to Security News