Known Vulnerabilities for MainWP by Mainwp
Listed below are 1 of the newest known vulnerabilities associated with "MainWP" by "Mainwp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57327 json | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | Not Provided | 2026-06-29 | 2026-06-29 |
| CVE-2026-27366 json | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | Not Provided | 2026-06-25 | 2026-06-29 |
| CVE-2026-4299 json | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.... | Not Provided | 2026-04-08 | 2026-04-13 |
| CVE-2025-64639 json | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Co... | Not Provided | 2025-12-16 | 2026-04-27 |
| CVE-2025-48298 json | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benj... | Not Provided | 2025-08-20 | 2026-04-23 |
| CVE-2025-31076 json | Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Server Side ... | Not Provided | 2025-03-28 | 2026-04-23 |
| CVE-2025-30932 json | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Co... | Not Provided | 2025-06-06 | 2026-04-23 |
| CVE-2024-35664 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid ... | Not Provided | 2024-06-04 | 2026-04-23 |
| CVE-2024-33680 json | Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from ... | Not Provided | 2024-04-26 | 2026-04-28 |
| CVE-2024-10783 json | The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to... | Not Provided | 2024-12-13 | 2026-04-08 |