
Proof-of-concept exploit and lab for CVE-2026-84753, an unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 via the mint-form-submit REST endpoint.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-84753
Mail Mint 1.31.0 - WPFunnels
I am @abraxas_null. Loopback lab. The client is CVE-2026-84753-Abraxas-Labs.py.
The function is named safe. Unauthenticated REST mint-form-submit copies extra fields into contact meta, then ContactModel::safe_unserialize_meta() maybe_unserializes them. Objects instantiate before the is_array discard. The JSON can still say the form is not valid. The class still ran. Patched in 1.31.1 (is_serialized reject, allowed_classes => false).
| CVE | CVE-2026-84753 · CVE.org |
| CWE | CWE-502 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | Mail Mint |
| Affected | all versions through 1.31.0 (inclusive) |
| Patched | 1.31.1 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
POST the public form twice with the same email and a serialized object in an extra field. First request stores. Second request loads. __wakeup / __destruct run in the WordPress process. A POP gadget on a real autoload is RCE. The lab ships a canary class, not a gadget.
Patchstack named object injection. I read FormAction::handle_form_submission, then safe_unserialize_meta. HTTP is REST, not an ajax action= of that name.
Harvest MM_NONCE= from the public page the way a visitor would. Two POSTs, same email, extra field is a serialized instance of the lab canary. Witness is POCWitness84753 in the body or debug.log.
Wrong turns: treating action=safe_unserialize_meta as a route; stopping at {"status":"success","message":"Form is not valid"} (that JSON is not a miss); hard-coding a nonce; calling this "WordPress unserializes meta" (core post meta is a different story).
Port 8088. Mail Mint 1.31.0. Seed form id 1 and page slug mm-lab-nonce.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-84753-Abraxas-Labs.py
Witness: POCWitness84753 from __wakeup / __destruct in the second POST body or debug.log. Form-invalid JSON without that string is not it.
Ways to lose without learning anything:
wp_rest nonceUpdate Mail Mint to 1.31.1 or newer. Re-run CVE-2026-84753-Abraxas-Labs.py against the patched build: POCWitness84753 must not appear.
Plugin directory: mail-mint
Trac browser: plugins.trac.wordpress.org/mail-mint
SVN tags: plugins.svn.wordpress.org/mail-mint
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.