Authorization Flaw in MainWP Child Reports Plugin for WordPress
CVE-2026-4299
What is CVE-2026-4299?
The MainWP Child Reports plugin for WordPress suffers from a vulnerability due to missing capability checks in the heartbeat_received() function within the Live_Update class. This issue affects all versions up to and including 2.2.6, allowing authenticated users with Subscriber-level access and above to exploit the WordPress Heartbeat API. By sending a specially crafted heartbeat request containing the 'wp-mainwp-stream-heartbeat' data key, attackers can gain unauthorized access to sensitive activity log entries, which disclose action summaries, user information, IP addresses, and additional contextual data. This makes it imperative for users to update to the latest version to mitigate potential security risks.
Affected Version(s)
MainWP Child Reports 0 <= 2.2.6