8.8
CVE-2026-105436
- EPSS 0.25%
- Veröffentlicht 08.10.2026 17:00:12
- Zuletzt bearbeitet 09.10.2026 16:17:21
- Erkennungen
WordPress MainWP Child plugin <= 6.2.1 - Deserialization of untrusted data vulnerability
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites <= 6.2.1 - Unauthenticated PHP Object Injection
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
Mögliche Gegenmaßnahme
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites: Update to version 6.2.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMainWP
≫
Produkt
MainWP Child
Default Statusunaffected
Version <=
6.2.1
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
Version
*-6.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.153 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://patchstack.com/database/wordpress/plugin/mainwp-child/vulnerability/wordpress-mainwp-child-plugin-6-2-1-deserialization-of-untrusted-data-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/8ad6ddec-e25f-4553-a116-25a44acdcbbf