โ† Back to Dashboard

CVE-2026-12255

HIGH NVD
CVSS Score
8.1
Severity
HIGH
Source
NVD
Published
Jul 27, 2026
Description

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

View Full Details โ† Back