CVE-2026-1258 | Mail Mint Plugin up to 1.19.2 on WordPress API Endpoint order-by/order-type/selectedCourses sql injection
A vulnerability was found in Mail Mint Plugin up to 1.19.2 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component API Endpoint. This manipulation of the argument order-by/order-type/selectedCourses causes sql injection.
This vulnerability is handled as CVE-2026-1258. The attack can be initiated remotely. There is not any exploit available.