PT-2026-64832 · WordPress · Mainwp Child

·

CVE-2026-12255

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MainWP Child WordPress plugin versions prior to 6.1.2
Description The site-registration request handler fails to verify the identity of the requester when password authentication is disabled for the targeted account. This allows an unauthenticated attacker to obtain a valid authentication session for that account, including those with administrator privileges, by specifying the login name in a single registration request.
Recommendations Update the MainWP Child WordPress plugin to version 6.1.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12255

Affected Products

Mainwp Child