CVE-2026-2025
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
04/03/2026
Last modified:
04/03/2026
Description
The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



