High 7.6
2025-09-22< 1.18.7
Mail Mint <= 1.18.6 - Authenticated (Administrator+) SQL Injection
Minimum safe version
1.19.5
Update to 1.19.5 or later to address 8 fixable vulnerabilities
Mail Mint <= 1.18.6 - Authenticated (Administrator+) SQL Injection
Mail Mint <= 1.19.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Mail Mint <= 1.19.2 - Authenticated (Administrator+) SQL Injection via Multiple API Endpoints
Mail Mint – Newsletters, Email Marketing, Automation, WooCommerce Emails, Post Notification, and more < 1.19.5 - Unauthenticated Information Disclosure
CVE-2026-23541
CVE-2025-11967
CVE-2025-58604
CVE-2025-47541