WordPress security by component
MainWP Child
Plugin description
MainWP Child is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.1.
Plugin slug:
mainwp-childLatest vulnerability
CVE-2026-12255: MainWP Child registration can create administrator sessions without authentication
MainWP Child before 6.1.2 fails to verify the requester's identity in its site-registration handler when password authentication is disabled for the named target account. An unauthenticated attacker can identify an existing username, including an administrator, and obtain an authenticated session for that user in a single registration request. The CNA record does not disclose the handler, username parameter or session-creation function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-12255
MainWP Child registration can create administrator sessions without authentication
MainWP Child before 6.1.2 fails to verify the requester's identity in its site-registration handler when password authentication is disabled for the named target account. An unauthenticated attacker can identify an existing username, including an administrator, and obtain an authenticated session for that user in a single registration request. The CNA record does not disclose the handler, username parameter or session-creation function.
|
6.1.2 |
CVE8.1
NVDPending
|
| Jun 25, 2026 |
CVE-2026-27366
MainWP Child: A security weakness
MainWP Child is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.1.1.
|
6.1.2 |
CVE7.5
NVDPending
|
| Dec 13, 2024 |
CVE-2024-10783
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites: Privilege escalation or authentication bypass
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Jun 27, 2023 |
CVE-2023-3132
MainWP Child: Sensitive information exposure
MainWP Child is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.9
NVD7.5
|
| Nov 23, 2021 |
CVE-2021-24877
MainWP Child: SQL injection
MainWP Child is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|