CVE · High

CVE-2024-10783 — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 5.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10783 MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 5.3.4 Missing Authorization High 8.1 < 5.3.4 5.3.4 2024-12-12

CVE-2024-10783

The MainWP Child plugin for WordPress versions up to 5.3.3 contains a privilege escalation vulnerability stemming from inadequate authorization verification in the register_site function, allowing unauthenticated users to gain administrative access on sites that have not yet been connected to the MainWP Dashboard and lack the unique security ID feature enabled. This vulnerability only impacts unconfigured installations and does not affect sites already connected to the MainWP Dashboard. Although versions 5.3.3 included an attempted fix, a bypass method was later identified that required the release of version 5.3.4 to fully resolve the issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.