PatchSiren cyber security CVE debrief
CVE-2026-105436 MainWP CVE debrief
CVE-2026-105436 is a deserialization of untrusted data vulnerability in the MainWP Child plugin for WordPress, affecting versions up to 6.2.1. This issue allows for object injection and has been rated as HIGH severity with a CVSS score of 8.8. Defenders should assess exposure and apply updates to prevent potential object injection attacks. The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. MainWP Child plugin versions up to 6.2.1 are affected, and version 6.2.2 is reported as unaffected.
- Vendor
- MainWP
- Product
- MainWP Child
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for WordPress installations with the MainWP Child plugin should assess exposure and apply updates to prevent potential object injection attacks.
Why it matters
CVE-2026-105436 is a deserialization of untrusted data vulnerability in the MainWP Child plugin for WordPress, allowing object injection and rated as HIGH severity with a CVSS score of 8.8. Defenders should prioritize verifying exposure and applying updates to prevent potential attacks.
- Verify exposure of MainWP Child plugin versions up to 6.2.1
- Apply updates to MainWP Child plugin to version 6.2.2 or later
- Monitor for potential object injection attacks
Technical summary
The MainWP Child plugin for WordPress has a deserialization of untrusted data vulnerability, affecting versions up to 6.2.1. This issue allows for object injection and has been rated as HIGH severity with a CVSS score of 8.8. The vulnerability can be exploited by injecting malicious data, potentially leading to object injection attacks. Defenders should prioritize verifying exposure of MainWP Child plugin versions up to 6.2.1 and applying updates to prevent potential object injection attacks.
Defensive priority
Defenders should prioritize verifying exposure of MainWP Child plugin versions up to 6.2.1 and applying updates to prevent potential object injection attacks.
Recommended defensive actions
- Verify MainWP Child plugin versions up to 6.2.1 for exposure
- Apply updates to MainWP Child plugin to version 6.2.2 or later
- Monitor for potential object injection attacks
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. MainWP Child plugin versions up to 6.2.1 are affected, and version 6.2.2 is reported as unaffected.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105436 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105436
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105436 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105436
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress MainWP Child plugin <= 6.2.1 - Deserialization of untrusted data vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105436.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.