Description
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
Published: 2026-07-27
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to obtain a valid authentication session for any account whose password authentication has been disabled. By submitting a single site‑registration request with the target login name, the attacker can trick MainWP Child’s request handler into creating a session for that account, including administrative users. The lack of identity verification makes it easy to hijack accounts that rely on passwordless authentication.

Affected Systems

The vulnerability affects installations of the MainWP Child WordPress plugin, specifically versions earlier than 6.1.2. Sources indicate the issue is present in all such releases regardless of the host site's WordPress configuration. No other vendor or product is listed as impacted.

Risk and Exploitability

The CVSS score of 8.1 indicates a high‑severity flaw. Because the attack requires no prior authentication and can be performed remotely via the site‑registration endpoint, the likelihood of exploitation is significant, with an EPSS score of < 1% indicating a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can bypass authentication by simply generating a registration request with the target login, suggesting that anyone with network access to the WordPress site can exploit the weakness. The vulnerability is particularly dangerous for instances where administrative accounts have password authentication disabled or where passwordless logins are used.

Generated by OpenCVE AI on August 3, 2026 at 18:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MainWP Child to version 6.1.2 or later.
  • Ensure that all accounts, especially administrators, have password authentication enabled to prevent passwordless access.
  • Disable or restrict the site‑registration endpoint if it is not needed, or limit its use to authenticated users only.

Generated by OpenCVE AI on August 3, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mainwp
Mainwp mainwp Child
Wordpress
Wordpress wordpress
Vendors & Products Mainwp
Mainwp mainwp Child
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
Title MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
References

Subscriptions

Mainwp Mainwp Child
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T15:50:54.586Z

Reserved: 2026-06-15T08:48:55.176Z

Link: CVE-2026-12255

cve-icon Vulnrichment

Updated: 2026-07-27T15:49:39.516Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T07:16:24.283

Modified: 2026-07-27T20:33:01.673

Link: CVE-2026-12255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:00:03Z

Weaknesses