CVE-2026-105436: WordPress MainWP Child plugin <= 6.2.1 - Deserialization of untrusted data vulnerability
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MainWP Child pluginto a version that resolves this vulnerability.Fixed in 6.2.2
Event History
Frequently Asked Questions
Which installations are affected?
MainWP Child versions through 6.2.1 are affected. The available data does not identify a fixed version.
Can this be exploited remotely without an account?
The CVSS vector indicates network-based exploitation with low attack complexity and no privileges required, but user interaction is required. The data does not specify what interaction is needed.
What is the potential impact of successful exploitation?
The vulnerability is rated high severity with a CVSS score of 8.8. Successful exploitation may affect confidentiality, integrity, and availability at high impact levels.