CVE-2026-12255
Received Received - Intake

Unauthenticated Account Takeover in MainWP Child WordPress Plugin

Vulnerability report for CVE-2026-12255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mainwp mainwp_child to 6.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the MainWP Child WordPress plugin versions before 6.1.2. It allows an unauthenticated attacker to bypass authentication and gain administrator access by exploiting a flaw in the site-registration request handler when password authentication is disabled. The attacker can obtain a valid session by submitting a single registration request with the target account's login name.

Detection Guidance

Check if your MainWP Child plugin version is below 6.1.2 by inspecting the plugin files or WordPress admin panel. Look for unauthorized administrator accounts or unexpected registration requests in server logs.

Impact Analysis

An attacker could gain full control of your WordPress site by exploiting this vulnerability, allowing them to install malicious plugins, steal data, or deface your website. Since it bypasses authentication, even accounts with password authentication disabled are vulnerable.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face fines or legal consequences if this flaw is exploited and sensitive data is compromised.

Mitigation Strategies

Update the MainWP Child plugin to version 6.1.2 or later immediately. Disable password authentication for accounts if not required and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart