Description
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
Published: 2026-10-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the MainWP Child plugin’s handling of untrusted serialized data, which permits object injection. An attacker who can supply crafted payloads to the plugin can instantiate arbitrary PHP objects, potentially leading to arbitrary code execution, data leakage, or defacement. This flaw is classified under CWE-502, indicating that input validation during deserialization is insufficient. The primary impact is a compromise of the WordPress site hosting the plugin, affecting confidentiality, integrity, and availability of site data and functions.

Affected Systems

The affected product is the MainWP Child WordPress plugin up to and including version 6.2.1. Users running MainWP Child 6.2.1 or earlier should update to 6.2.2 or later, as this version removes the flawed deserialization logic. All WordPress sites that rely on this plugin are at risk, regardless of the overall WordPress version.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity rating. While the EPSS score is not available, the lack of an EPSS value does not diminish the inherent risk; the flaw enables arbitrary code execution with moderate complexity. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in known attacks. The attack vector is inferred to be remote, exploiting the plugin’s exposure to external or internal data sources such as HTTP requests or REST API endpoints. Given the serious nature of the flaw and the availability of a patch, the risk of exploitation remains significant if the plugin is not updated.

Generated by OpenCVE AI on October 8, 2026 at 19:22 UTC.

Remediation

Vendor Solution

Update the WordPress MainWP Child plugin to the latest available version (at least 6.2.2).


OpenCVE Recommended Actions

  • Update the plugin to version 6.2.2 or later to remove the insecure deserialization.
  • Restrict the plugin’s data entry points to trusted administrators only, preventing unauthenticated or untrusted users from supplying payloads.
  • Deploy a web application firewall with rules that detect and block object injection attempts as an additional layer of defense.

Generated by OpenCVE AI on October 8, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
Title WordPress MainWP Child plugin <= 6.2.1 - Deserialization of untrusted data vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T17:00:12.300Z

Reserved: 2026-10-05T13:00:43.469Z

Link: CVE-2026-105436

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T17:17:12.363

Modified: 2026-10-08T17:24:11.230

Link: CVE-2026-105436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data