PT-2026-64832 · WordPress · Mainwp Child
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MainWP Child WordPress plugin versions prior to 6.1.2
Description
The site-registration request handler fails to verify the identity of the requester when password authentication is disabled for the targeted account. This allows an unauthenticated attacker to obtain a valid authentication session for that account, including those with administrator privileges, by specifying the login name in a single registration request.
Recommendations
Update the MainWP Child WordPress plugin to version 6.1.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mainwp Child