Junglewise Threat Intelligence

CVE-2026-27366: MainWP Child broken access control in WordPress plugin

CVE-2026-27366 · Severity: high · CVSS 7.5 · Published 2026-06-25

Executive brief

MainWP Child is a WordPress plugin used to connect individual websites to a central management dashboard. A security flaw in versions 6.1.1 and earlier allows unauthorized individuals to bypass access controls, potentially leading to unauthorized administrative actions or site takeover. This vulnerability requires a legitimate administrator to interact with a malicious link or page to be successfully exploited.

Technical details

A broken access control vulnerability exists in the MainWP Child plugin for WordPress due to missing authorization or nonce checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute privileged functions. Exploitation is considered high complexity as it requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page. Successful exploitation could allow an attacker to intercept or manipulate the connection between the child site and the MainWP Dashboard. The issue is resolved in version 6.1.2.

Affected products

  • MainWP MainWP Child <= 6.1.1

Timeline

  • 2025-11-24: other: Vulnerability reported by researcher mcdruid
  • 2026-06-23: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats