CVE-2025-11967: Getwpfunnels Mail Mint – Email Marketing, Newsletter, Email Automation & Woocommerce Emails
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import function in all versions up to, and including, 1.18.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected products
- Getwpfunnels Mail Mint – Email Marketing, Newsletter, Email Automation & Woocommerce Emails: up to and including 1.18.10
Published 2025-11-08. Last modified 2026-10-07.