
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23541 is a Missing Authorization (Broken Access Control) vulnerability in the WPFunnels Mail Mint WordPress plugin that allows unauthenticated remote attackers to access functionality not properly constrained by ACLs. It affects Mail Mint versions up to and including 1.19.4, with version 1.19.5 containing the fix. The vulnerability was reported by security researcher Denver Jackson on September 3, 2025, and publicly disclosed on February 18–19, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, Feedly).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged functionality. An unauthenticated remote attacker can send crafted network requests to trigger restricted plugin actions without supplying valid credentials, nonce tokens, or capability checks. The attack requires no user interaction, no special privileges, and has low complexity, making it trivially exploitable over the network (Patchstack, Feedly).
Successful exploitation results in a high confidentiality impact — unauthenticated attackers can access sensitive data managed by the Mail Mint plugin (e.g., subscriber lists, email campaign data, contact information) without authorization. Integrity and availability are not directly impacted per the CVSS scoring. Given the plugin's role in email marketing and lead management, exposure of subscriber PII and campaign data represents a significant data breach risk for affected WordPress sites (Patchstack).
Patchstack has flagged this vulnerability as "Known to be exploited" and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is 0.017% (0.000170), indicating a relatively low but non-zero probability of exploitation in the near term. No specific threat actor attribution is publicly available at this time. The vulnerability requires no authentication, making it accessible to any attacker with network access to a vulnerable WordPress installation (Patchstack, Feedly).
wp-content/plugins/mail-mint/.wp-json/ enumeration or source code review) to locate endpoints lacking capability or nonce checks./wp-json/mail-mint/ or similar) from external IPs; high-volume automated requests to plugin endpoints indicative of mass scanning.The vendor (WPFunnels Team) has released Mail Mint version 1.19.5 which patches this vulnerability — all users should update immediately. Patchstack has also issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until the plugin update is applied. If updating is not immediately possible, consider temporarily deactivating the Mail Mint plugin or restricting access to WordPress REST API endpoints via firewall rules (Patchstack).
Patchstack, which operates an active Vulnerability Disclosure Program (VDP) with the WPFunnels team, classified this as high priority and noted it is expected to be leveraged in mass-exploit campaigns. The vulnerability was credited to researcher Denver Jackson. A Bluesky post referencing the CVE was observed in June 2026, suggesting ongoing community awareness (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."