CVE-2026-57327: WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability
Published Jun 29, 2026
·Updated
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
Affected Software
1 affected component
MainWP MainWP WordPress plugin<=6.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MainWP Pluginto a version that resolves this vulnerability.Fixed in 6.1.2
Event History
Jun 29, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57327?
The severity of CVE-2026-57327 is medium, with a CVSS score of 6.3.
2
What type of vulnerability is CVE-2026-57327?
CVE-2026-57327 is classified as a Broken Access Control vulnerability affecting the MainWP WordPress plugin.
3
How do I fix CVE-2026-57327?
To fix CVE-2026-57327, update the MainWP plugin to version 6.1.2 or newer.
4
Who is affected by CVE-2026-57327?
CVE-2026-57327 affects users of the MainWP plugin with subscriber roles who may exploit the access control issues.
5
When was CVE-2026-57327 published?
CVE-2026-57327 was published on June 29, 2026.