Mail Mint WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Mail Mint plugin for WordPress, affecting all versions through 1.19.2. The issue arises from inadequate nonce validation in the 'create_or_update_note' function, allowing unauthenticated attackers to manipulate contact notes by deceiving site administrators into clicking a link. This vulnerability also lacks proper data sanitization and escaping, potentially leading to stored Cross-Site Scripting (XSS) attacks.

Impact

Exploitation of this vulnerability could result in unauthorized modifications to contact notes, with the possibility of introducing malicious scripts that are stored and executed in the context of the user.

Reproduction

To reproduce this vulnerability, an attacker must craft a request to the 'create_or_update_note' endpoint without a valid nonce. This can be done by tricking an administrator into clicking a link that sends the request, such as through a phishing email or a compromised website.

Remediation

Users are advised to update the Mail Mint plugin to version 1.19.3 or later, where this vulnerability has been patched.

Added: Feb 3, 2026, 7:38 AM
Updated: Feb 3, 2026, 7:38 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.2
remediation
0.0
relevance
2.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.