Resources /
WordPress Plugins /
MainWP Child Reports
PLUGIN SECURITY
Is MainWP Child Reports safe?
The MainWP Child Report plugin tracks changes to Child sites for the Pro Reports Extension.
What this plugin does
- Slug:
mainwp-child-reports
- Author: mainwp
- 100000+ active installs
- 86/100 rating (6 reviews on wordpress.org)
- 1661200 all-time downloads
- On WordPress.org since 2015-08-10
child reportsMainWPMainWP ChildMainWP Child ReportsMainWP Pro Reports Extension
Maintenance status
- Last updated: 2026-05-21 3:31pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
4 known CVEs on file for MainWP Child Reports.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7492
|
MainWP Child Reports [mainwp-child-reports] < 2.2.1 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 2.2.1
|
2.2.1 |
2024-08-07 |
—
|
|
CVE-2024-33680
|
MainWP Child Reports [mainwp-child-reports] < 2.2 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 2.2
|
2.2 |
2024-04-26 |
—
|
|
CVE-2021-24754
|
MainWP Child Reports [mainwp-child-reports] < 2.0.8 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.2
|
< 2.0.8
|
2.0.8 |
2021-09-20 |
—
|
|
CVE-2026-4299
|
MainWP Child Reports [mainwp-child-reports] < 2.3 |
— |
Unknown
|
< 2.3
|
2.3 |
0000-00-00 |
—
|
CVE-2024-7492
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can be leveraged for privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is only exploitable on multisite instances.
Source:
CVE.org
CVE-2024-33680
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the uninstall() function. This makes it possible for unauthenticated attackers to deactivate the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2021-24754
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Source:
CVE.org
CVE-2026-4299
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain MainWP Child Reports activity log entries (including action summaries, user information, IP addresses, and contextual data) via the WordPress Heartbeat API by sending a crafted heartbeat request with the 'wp-mainwp-stream-heartbeat' data key.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.