Executive brief
MainWP Child is a WordPress plugin used to connect websites to a central management dashboard. A security flaw in this plugin allows unauthorized individuals to bypass login security and gain full administrative access to a website. This could lead to complete site takeover, data theft, or the installation of malicious software without needing a password.
Technical details
An authentication bypass vulnerability exists in the MainWP Child plugin for WordPress due to insufficient identity verification in the site-registration request handler. When password authentication is disabled for a specific account, the plugin fails to validate the requester's identity during the registration process. An unauthenticated remote attacker can exploit this by sending a single registration request specifying a target username (such as an administrator). Successful exploitation allows the attacker to obtain a valid authentication session as the targeted user, leading to full site compromise. This issue is fixed in version 6.1.2.
Affected products
- MainWP MainWP Child < 6.1.2
Timeline
- 2026-07-06: disclosed: Publicly published via WPScan
- 2026-07-27: advisory: CVE published to NVD dataset
- 2026-07-27: patched: Fixed in version 6.1.2