Executive brief
MainWP is a popular WordPress plugin used by administrators to manage multiple WordPress sites from a single dashboard. A security flaw in versions 6.1.1 and earlier allows users with low-level 'Subscriber' accounts to bypass security restrictions and perform actions they should not be authorized to do. This could lead to unauthorized changes to the management dashboard or access to sensitive site information, potentially compromising the central management of multiple websites.
Technical details
MainWP versions up to and including 6.1.1 are vulnerable to a Broken Access Control flaw (CWE-862: Missing Authorization). The vulnerability exists because the plugin fails to properly validate user permissions or implement sufficient authorization checks on certain functions. An attacker authenticated with a low-privilege 'Subscriber' role can exploit this to execute actions typically reserved for higher-privileged users. This could result in unauthorized data modification or information disclosure across the managed WordPress network. The issue is resolved in version 6.1.2.
Affected products
- MainWP MainWP <= 6.1.1
Timeline
- 2026-03-20: other: Reported by researcher 'sleeper'
- 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-29: patched: Patch released in version 6.1.2