CVE-2025-59570

7.6

WPFunnels · Mail Mint

A SQL injection vulnerability exists in the Mail Mint plugin for WordPress, allowing an authenticated administrator to inject malicious SQL commands.

Executive summary

The Mail Mint WordPress plugin is vulnerable to SQL injection, which could allow an authenticated attacker with administrative privileges to compromise sensitive database information.

Vulnerability

This vulnerability is a SQL injection flaw (CWE-89) triggered by improper neutralization of special elements in SQL commands. The vulnerability requires the attacker to have administrative privileges to execute the malicious queries.

Business impact

Successful exploitation of this vulnerability enables an attacker to perform unauthorized database queries, potentially leading to the exposure of sensitive user or system data. With a CVSS score of 7.6, this flaw presents a significant risk to data confidentiality and integrity. If leveraged, the breach could result in severe reputational damage and potential regulatory non-compliance regarding data protection.

Remediation

Immediate Action: Since no specific patch version is currently identified, administrators should monitor the vendor website for security updates and apply them immediately upon release.

Proactive Monitoring: Security teams should review database query logs for suspicious patterns or anomalous syntax that deviates from standard plugin operations.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to detect and block common SQL injection patterns to provide a layer of virtual patching until an official update is available.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized code available for this vulnerability.

Analyst recommendation

Given the high CVSS severity, organizations utilizing the Mail Mint plugin must prioritize the mitigation of this risk. Administrators should restrict administrative access to the WordPress dashboard to the minimum number of necessary personnel while awaiting a security patch from the vendor.

More WPFunnels CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written
  5. Fix documented version 1.18.7 per Wordfence

Sources

Originally found and disclosed by Le Cong Danh (vodanh) | Patchstack Bug Bounty Program, per the CVE Program record.