CVE-2026-12255
Description
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | MainWP Child | — | 0 < 6.1.2 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-287 Improper Authentication |