CVE-2026-12255: MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MainWP Child (WordPress plugin)to a version that resolves this vulnerability.Fixed in 6.1.2 - Compensating control
Mitigate unauthenticated access to the MainWP Child site-registration endpoint by restricting network access (e.g., via firewall/ACL/WAF) so only trusted sources can reach the site-registration request handler.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12255?
The severity of CVE-2026-12255 is rated as 89, indicating a high risk.
How do I fix CVE-2026-12255?
To fix CVE-2026-12255, you should update the MainWP Child plugin to version 6.1.2 or higher.
What does CVE-2026-12255 exploit?
CVE-2026-12255 exploits the lack of identity verification in the site-registration request handler of the MainWP Child plugin.
Who is affected by CVE-2026-12255?
Users of the MainWP Child plugin versions prior to 6.1.2 are affected by CVE-2026-12255.
Can an attacker exploit CVE-2026-12255 without authentication?
Yes, an attacker can exploit CVE-2026-12255 without authentication due to the weakness in the plugin's handling of passwordless site registration.