The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog
History

Wed, 04 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Getwpfunnels
Getwpfunnels mail Mint
Wordpress
Wordpress wordpress
Vendors & Products Getwpfunnels
Getwpfunnels mail Mint
Wordpress
Wordpress wordpress

Wed, 04 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog
Title Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-03-04T06:00:08.044Z

Updated: 2026-03-04T17:09:15.123Z

Reserved: 2026-02-05T20:41:56.158Z

Link: CVE-2026-2025

cve-icon Vulnrichment

Updated: 2026-03-04T17:06:20.425Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T06:16:11.297

Modified: 2026-03-04T18:16:29.953

Link: CVE-2026-2025

cve-icon Redhat

No data.