CVE-2026-23541: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-23541 is a Missing Authorization (Broken Access Control) vulnerability in the WPFunnels Mail Mint WordPress plugin that allows unauthenticated remote attackers to access functionality not properly constrained by ACLs. It affects Mail Mint versions up to and including 1.19.4, with version 1.19.5 containing the fix. The vulnerability was reported by security researcher Denver Jackson on September 3, 2025, and publicly disclosed on February 18–19, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged functionality. An unauthenticated remote attacker can send crafted network requests to trigger restricted plugin actions without supplying valid credentials, nonce tokens, or capability checks. The attack requires no user interaction, no special privileges, and has low complexity, making it trivially exploitable over the network (Patchstack, Feedly).

Impact

Successful exploitation results in a high confidentiality impact — unauthenticated attackers can access sensitive data managed by the Mail Mint plugin (e.g., subscriber lists, email campaign data, contact information) without authorization. Integrity and availability are not directly impacted per the CVSS scoring. Given the plugin's role in email marketing and lead management, exposure of subscriber PII and campaign data represents a significant data breach risk for affected WordPress sites (Patchstack).

Exploitability

Patchstack has flagged this vulnerability as "Known to be exploited" and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is 0.017% (0.000170), indicating a relatively low but non-zero probability of exploitation in the near term. No specific threat actor attribution is publicly available at this time. The vulnerability requires no authentication, making it accessible to any attacker with network access to a vulnerable WordPress installation (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Mail Mint plugin (versions ≤ 1.19.4) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at wp-content/plugins/mail-mint/.
  2. Identify unprotected endpoints: Review the plugin's registered REST API routes or AJAX actions (e.g., via wp-json/ enumeration or source code review) to locate endpoints lacking capability or nonce checks.
  3. Craft unauthenticated request: Send a direct HTTP GET or POST request to the identified unprotected endpoint without authentication headers or nonce tokens.
  4. Access restricted data: The server processes the request without authorization validation, returning sensitive plugin data such as subscriber lists, contact records, or campaign details to the attacker (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to Mail Mint plugin REST API endpoints (e.g., /wp-json/mail-mint/ or similar) from external IPs; high-volume automated requests to plugin endpoints indicative of mass scanning.
  • Logs: WordPress access logs showing repeated requests to Mail Mint plugin endpoints without authentication cookies or nonce parameters; 200 OK responses to requests that should require authentication.
  • File System: No direct file system artifacts expected for this read-only access control bypass, but monitor for follow-on activity such as new admin accounts or uploaded files if chained with other vulnerabilities.

Mitigation and workarounds

The vendor (WPFunnels Team) has released Mail Mint version 1.19.5 which patches this vulnerability — all users should update immediately. Patchstack has also issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until the plugin update is applied. If updating is not immediately possible, consider temporarily deactivating the Mail Mint plugin or restricting access to WordPress REST API endpoints via firewall rules (Patchstack).

Community reactions

Patchstack, which operates an active Vulnerability Disclosure Program (VDP) with the WPFunnels team, classified this as high priority and noted it is expected to be leveraged in mass-exploit campaigns. The vulnerability was credited to researcher Denver Jackson. A Bluesky post referencing the CVE was observed in June 2026, suggesting ongoing community awareness (Feedly, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management