Deserialization of Untrusted Data Issue in MainWP Child Plugin by MainWP
CVE-2026-105436

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105436?

The MainWP Child plugin has a security flaw that enables deserialization of untrusted data, potentially allowing for object injection vulnerabilities. This issue poses significant risks to user data and the integrity of the affected system as it allows an attacker to manipulate the application in ways that could lead to unauthorized access or execution of malicious code.

Affected Version(s)

MainWP Child 0 <= 6.2.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad | Patchstack Bug Bounty Program
.