MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites <= 6.2.1 - Unauthenticated PHP Object Injection via Clone/Restore Database Values

High 7.5 CWE-502Fixed in 6.2.2
ID
WPSEC-2026-0460
Plugin
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites (mainwp-child)
Affected
all versions before 6.2.2
Remediation
Update to 6.2.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness
CWE-502
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites on WPSec AttackSurface
Fix released
Published

Description

The MainWP Child plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.1 via deserialization of untrusted input in the recursive_unserialize_replace function. When a site is cloned or restored, every serialized-looking value in the restored database is passed to unserialize() without restricting allowed classes. This makes it possible for unauthenticated attackers to place a serialized PHP object in a stored value they can write, such as a comment, which is instantiated when an administrator later clones or restores a backup containing that value. Impact depends on a POP chain being available through the site's installed plugins or themes, which could allow file deletion, sensitive data retrieval, or code execution.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0