PatchSiren

MainWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MainWP CVE published 2026-07-27

CVE-2026-12255

The MainWP Child WordPress plugin before 6.1.2 has a vulnerability in its site-registration request handler. When password authentication has been disabled for a targeted account, the plugin does not verify the requester's identity. This allows an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator account, by simply naming its login in a single re [truncated]

HIGH MainWP CVE published 2026-06-25

CVE-2026-27366

CVE-2026-27366 is a high-severity vulnerability in the MainWP Child plugin versions <= 6.1.1. It allows unauthenticated broken access control, potentially enabling attackers to access sensitive areas of the website without proper authentication. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on June 25, 2026, and last modified on June 29, 2026. The vendor [truncated]

MEDIUM mainwp CVE published 2026-04-08

CVE-2026-4299

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to obtain MainWP Child Reports activity log entries via the WordPress Heartbeat API. The vulnerability is due to a missing capability check in the heartbeat_received() function in the Live_ [truncated]