What is CVE-2026-12255?
CVE-2026-12255 is a critical vulnerability in the MainWP Child WordPress plugin before version 6.1.2, where the site-registration request handler fails to verify the requester's identity when password authentication is disabled for the targeted account. This allows an unauthenticated attacker to obtain a valid authentication session for that account. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-12255, MainWP Child WordPress plaginində 6.1.2 versiyasından əvvəl mövcud olan kritik bir boşluqdur. Bu boşluq, parol autentifikasiyası deaktiv edilmiş hesablar üçün sayt qeydiyyatı sorğularında şəxsiyyət doğrulamasının aparılmaması səbəbindən autentifikasiya olunmamış hücumçuya həmin hesabın etibarlı sessiyasını ələ keçirməyə imkan verir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What is the root cause of CVE-2026-12255?
The vulnerability stems from the MainWP Child plugin's site-registration request handler failing to verify the requester's identity when password authentication is disabled for the targeted account.
Which versions are affected by CVE-2026-12255, and how should it be fixed?
This vulnerability affects all versions of the MainWP Child plugin before 6.1.2. It is strongly recommended to update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.