Impact
This vulnerability allows an unauthenticated attacker to obtain a valid authentication session for any account whose password authentication has been disabled. By submitting a single site‑registration request with the target login name, the attacker can trick MainWP Child’s request handler into creating a session for that account, including administrative users. The lack of identity verification makes it easy to hijack accounts that rely on passwordless authentication.
Affected Systems
The vulnerability affects installations of the MainWP Child WordPress plugin, specifically versions earlier than 6.1.2. Sources indicate the issue is present in all such releases regardless of the host site's WordPress configuration. No other vendor or product is listed as impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity flaw. Because the attack requires no prior authentication and can be performed remotely via the site‑registration endpoint, the likelihood of exploitation is significant, with an EPSS score of < 1% indicating a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can bypass authentication by simply generating a registration request with the target login, suggesting that anyone with network access to the WordPress site can exploit the weakness. The vulnerability is particularly dangerous for instances where administrative accounts have password authentication disabled or where passwordless logins are used.
OpenCVE Enrichment