CVE · High

CVE-2024-7492 — MainWP Child Reports [mainwp-child-reports] < 2.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7492 MainWP Child Reports [mainwp-child-reports] < 2.2.1 Cross-Site Request Forgery (CSRF) High 8.8 < 2.2.1 2.2.1 2024-08-07

CVE-2024-7492

The MainWP Child Reports plugin for WordPress has a security flaw in its network settings handling, specifically affecting the network_options_action() function. In versions up to and including 2.2, this vulnerability allows an attacker who can manipulate a site administrator's actions to update arbitrary options without proper authentication. This exploit is limited to multisite setups where an unauthenticated individual can trick an admin into performing a malicious action via a manipulated link or request.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.