๐Ÿ” CVE Alert

CVE-2026-12255

UNKNOWN 0.0

MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

Vendor unknown
Product mainwp child
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown mainwp child

Be the first to know when new unknown vulnerabilities affecting unknown mainwp child are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MainWP Child
0 < 6.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6ecd37bf-f48a-4f7f-8a93-e7f0475371af/

Credits

Khaled Alenazi (Nxploited) WPScan