CVE-2024-10783
The MainWP Child plugin for WordPress versions up to 5.3.3 contains a privilege escalation vulnerability stemming from inadequate authorization verification in the register_site function, allowing unauthenticated users to gain administrative access on sites that have not yet been connected to the MainWP Dashboard and lack the unique security ID feature enabled. This vulnerability only impacts unconfigured installations and does not affect sites already connected to the MainWP Dashboard. Although versions 5.3.3 included an attempted fix, a bypass method was later identified that required the release of version 5.3.4 to fully resolve the issue.
Based on public CVE data (MITRE/NVD).