Junglewise Threat Intelligence

CVE-2026-12255: MainWP Child authentication bypass in site-registration handler

CVE-2026-12255 · Severity: info · CVSS 8.1 · Published 2026-07-27

Executive brief

MainWP Child is a WordPress plugin used to connect websites to a central management dashboard. A security flaw in this plugin allows unauthorized individuals to bypass login security and gain full administrative access to a website. This could lead to complete site takeover, data theft, or the installation of malicious software without needing a password.

Technical details

An authentication bypass vulnerability exists in the MainWP Child plugin for WordPress due to insufficient identity verification in the site-registration request handler. When password authentication is disabled for a specific account, the plugin fails to validate the requester's identity during the registration process. An unauthenticated remote attacker can exploit this by sending a single registration request specifying a target username (such as an administrator). Successful exploitation allows the attacker to obtain a valid authentication session as the targeted user, leading to full site compromise. This issue is fixed in version 6.1.2.

Affected products

  • MainWP MainWP Child < 6.1.2

Timeline

  • 2026-07-06: disclosed: Publicly published via WPScan
  • 2026-07-27: advisory: CVE published to NVD dataset
  • 2026-07-27: patched: Fixed in version 6.1.2

References

Related threats