CVE-2024-10783

HIGH NUCLEI

MainWP Child <5.2 - Privilege Escalation

Title source: llm

Description

The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it possible for unauthenticated attackers to log in as an administrator on instances where MainWP Child is not yet connected to the MainWP Dashboard. IMPORTANT: this only affects sites who have MainWP Child installed and have not yet connected to the MainWP Dashboard, and do not have the unique security ID feature enabled. Sites already connected to the MainWP Dashboard plugin and do not have the unique security ID feature enabled, are NOT affected and not required to upgrade. Please note versions up to 5.3.3 contained a patch, though a bypass was discovered and not addressed until version 5.3.4.

Nuclei Templates (1)

WordPress Plugin MainWP Child - Authentication Bypass
HIGHVERIFIEDby Sean Murphy,iamnoooob,rootxharsh,pdresearch

Scores

CVSS v3 8.1
EPSS 0.0329
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (2)
mainwp/MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites < 5.2
mainwp/MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites < 5.3.3
Published Dec 13, 2024
Tracked Since Feb 18, 2026