Authentication Bypass in MainWP Child WordPress Plugin
CVE-2026-12255
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 27 July 2026
Badges
What is CVE-2026-12255?
The MainWP Child plugin for WordPress prior to version 6.1.2 contains a significant flaw that fails to verify the identity of the requester during site-registration requests. When password authentication is disabled for the targeted account, this vulnerability enables an unauthenticated attacker to register and thereby gain a valid authentication session as the account holder, which could include administrative accounts. Successful exploitation allows unauthorized access to sensitive functionalities within the WordPress environment.
Affected Version(s)
MainWP Child 0 < 6.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.