Mail Mint (WPFunnels) Unauthenticated PHP Object Injection

Release Date: 3rd September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and marketing/website teams that operate a WordPress or WooCommerce site using the Mail Mint email marketing automation plugin by WPFunnels. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-84753 is a critical, unauthenticated PHP Object Injection vulnerability in Mail Mint, a WordPress email marketing, newsletter, and automation plugin by WPFunnels with over 4,000 active installations and a 4.7-star rating, used to send WooCommerce transactional emails and run automated marketing campaigns. The flaw allows an attacker to submit specially-crafted serialized PHP data that the plugin deserializes without validating its origin or type.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-84753
  2. https://wordpress.org/plugins/mail-mint/