CVE-2026-10196
Critical · CVSS 9.8Published 2026-09-05
CVSS
9.8
Critical
EPSS
—
exploit probability
Active Exploit
No
not yet listed
What is CVE-2026-10196?
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1.
CVSS Score Explained
CVSS 9.8 is Critical — the highest severity tier. Attackers can likely exploit this remotely with no authentication and cause full system compromise. Patch immediately.
EPSS Exploitation Probability
No EPSS score yet — model needs more data on this CVE.
References & Patches
- ›https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/app/API/Actions/Frontend/FormAction.php#L59
- ›https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/app/Database/models/ContactModel.php#L460
- ›https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/vendor/posthog/posthog-php/lib/Consumer/ForkCurl.php#L96
- ›https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/API/Actions/Frontend/FormAction.php#L59
- ›https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/Database/models/ContactModel.php#L460
- ›https://plugins.trac.wordpress.org/browser/mail-mint/trunk/vendor/posthog/posthog-php/lib/Consumer/ForkCurl.php#L96
- ›https://plugins.trac.wordpress.org/changeset/3545065/
- ›https://plugins.trac.wordpress.org/changeset/3675453/
- ›https://www.wordfence.com/threat-intel/vulnerabilities/id/76c073d9-9572-43e4-82eb-49adf678535b?source=cve
Track vulnerabilities for your stack
Tell us what tech you run — Node.js, Python, Java, nginx, whatever — and get a weekly email when new CVEs affect it.
Recent CVEs
- CVE-2026-76160Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.—
- CVE-2026-76161Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.—
- CVE-2026-86150A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.2.0
- CVE-2026-86148A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.9.4
- CVE-2026-86149A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.9.4
- CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)8.8