Feed/CVE-2026-2025
CVE-2026-2025HIGHCVSS 7.5

CVE-2026-2025

Published Mar 4, 2026·Updated Jun 17, 2026

NVD Description

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

Public Exploits & PoCs4 found

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free