CVE-2026-2025Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-04); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Mentions · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-16: 1Technical Details · 2026-03-04: 4Technical Details · 2026-03-16: 103-0403-0503-16
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure4
2026-03-051
General1
2026-03-161
Disclosure1
Full discourse6 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-2025 - high 🚨 Mail Mint < 1.19.5 - Unauthenticated Email Disclosure > Mail Mint WordPress plugin < 1.19.5 contains an information disclosure vulnerability ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-2025 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a high‑severity, unauthenticated email disclosure vulnerability in Mail Mint WordPress plugin versions below 1.19.5 and provides a link to a Nuclei template library for detection.

    00002155
    901 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2025 🚨 Risk Level: Unknown 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2025 #CVE-2026-2025 #CVE  #Wordpress #CyberSecurity #InfoSec https://t.co/zRPWRDqCmR

    Post summary

    A terse CVE alert is shared, listing the CVE ID and affected product, but lacking deeper technical or operational details.

    0000032
    65 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2025 Unauthenticated Email Addressevalation in Mail WordPress Plugin Before Mail Mint mint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2025

    Post summary

    The post announces CVE-2026-2025, highlighting an unauthenticated email address evaluation vulnerability in the Mail WordPress Plugin, but provides no PoC, exploit code, or patch information.

    0000061
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2025 - Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure Intel Report: http://cyberbivash.blogspot.com/2026/03/cve-2026-2025-mail-mint-1195.html

    Post summary

    A new CVE-2026-2025 affecting Mail Mint versions below 1.19.5 allows unauthenticated email disclosure; the post does not provide PoC, exploit code, or patch details.

    0000032
    344 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2025 The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the em… https://www.cve.org/CVERecord?id=CVE-2026-2025 ----- Traducción: CVE-2026-2025 The… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2025, describing an unauthenticated REST API endpoint in the Mail Mint WordPress plugin that can expose data, but provides no PoC, exploit, or patch details.

    0000030
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2025 The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the em… https://www.cve.org/CVERecord?id=CVE-2026-2025

    Post summary

    The CVE highlights an unauthenticated access flaw in the Mail Mint WordPress plugin's REST API endpoint, allowing data retrieval without proper authorization.

    00000279
    56.6K followersView on X

Explore more