CVE-2026-12255 PUBLISHED

MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration

Assigner: WPScan
Reserved: 15.06.2026 Published: 27.07.2026 Updated: 27.07.2026

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

Product Status

Vendor Unknown
Product MainWP Child
Versions Default: unaffected
  • affected from 0 to 6.1.2 (excl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE