SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12255

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The MainWP Child WordPress plugin prior to version 6.1.2 is vulnerable due to a lack of identity verification in its site-registration request handler, particularly when password authentication is disabled. This flaw allows unauthenticated attackers to gain valid authentication sessions, potentially compromising accounts with administrative privileges. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-12255
Severity
HIGH
CVSS
8.1
EPSS
0.27%
WordPress

Original NVD Description

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.