plugin

Mainwp Vulnerabilities

17 known security issues reported for the Mainwp WordPress plugin. Most recent disclosed Jun 29, 2026.

3 high 3 medium 1 low

Running Mainwp on your site? Check whether your installed version is affected.

Scan your site free

MainWP Dashboard: Self-hosted WordPress Management for Agencies <= 6.1.1 - Missing Authorization

medium

The MainWP Dashboard: Self-hosted WordPress Management for Agencies plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an...

CVSS:
4.3
Affected:
up to 6.1.1
Fixed in:
6.1.2
Disclosed:
Jun 29, 2026

CVE-2026-57327 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] <= 5.3.4

unknown
Affected:
up to 5.3.4
Fixed in:
5.3.4
Disclosed:
Mar 27, 2025

CVE-2025-28253 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 3.1.3

unknown

[en] The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it p...

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Oct 16, 2024

CVE-2016-15041 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 5.0

unknown

[en] The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated...

Affected:
up to 5.0
Fixed in:
5.0
Disclosed:
Mar 13, 2024

CVE-2024-1642 on NVD →

MainWP Dashboard <= 4.6.0.1 - Cross-Site Request Forgery via posting_bulk

medium

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated atta...

CVSS:
4.3
Affected:
up to 4.6.0.1
Fixed in:
5.0
Disclosed:
Feb 27, 2024

CVE-2024-1642 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 4.4.3.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.

Affected:
up to 4.4.3.4
Fixed in:
4.4.3.4
Disclosed:
Dec 20, 2023

CVE-2023-38519 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 4.5.1.3

unknown

[en] The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-l...

Affected:
up to 4.5.1.3
Fixed in:
4.5.1.3
Disclosed:
Nov 22, 2023

CVE-2023-6164 on NVD →

MainWP <= 4.4.3.3 - Authenticated (Administrator+) SQL Injection

high

The MainWP plugin for WordPress is vulnerable to SQL Injection via the 'tags' parameter in versions up to, and including, 4.4.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administra...

CVSS:
7.2
Affected:
up to 4.4.3.3
Fixed in:
4.4.3.4
Disclosed:
Nov 9, 2023

CVE-2023-38519 on NVD →

MainWP Dashboard <= 4.5.1.2 - Authenticated(Administrator+) CSS Injection

low

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
2.2
Affected:
up to 4.5.1.2
Fixed in:
4.5.1.3
Disclosed:
Oct 20, 2023

CVE-2023-6164 on NVD →

MainWP Dashboard <= 4.2.4.1 - Cross-Site Request Forgery

medium

The MainWP Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.4.1. This is due to missing nonce validation on the render() and render_restore() function. This makes it possible for unauthenticated attackers to force site administrators to log into site's man...

CVSS:
4.3
Affected:
up to 4.2.4.1
Fixed in:
4.2.5
Disclosed:
Jun 21, 2022

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 4.2.5

unknown

The MainWP Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.4.1. This is due to missing nonce validation on the render() and render_restore() function. This makes it possible for unauthenticated attackers to force site administrators to log into site's man...

Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
Jun 21, 2022

MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting

high

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possib...

CVSS:
7.2
Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Apr 29, 2016

CVE-2016-15041 on NVD →

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 3.1.3

unknown

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possib...

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Apr 29, 2016

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 3.1.3

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update this plugin.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Apr 29, 2016

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 2.0.23

unknown

There is an unknown issue in this plugin. Upgrade this plugin.

Affected:
up to 2.0.23
Fixed in:
2.0.23
Disclosed:
Aug 8, 2015

MainWP Dashboard and MainWP Child <= 2.0.22 - Unspecified Vulnerability

high

Unspecified vulnerability in the MainWP Dashboard and MainWP Child plugins in versions up to and including 2.0.22 for WordPress has unspecified impact and remote attack vectors.

CVSS:
7.3
Affected:
up to 2.0.22
Fixed in:
2.0.23
Disclosed:
Aug 7, 2015

MainWP Dashboard: WordPress Management without the SaaS [mainwp] < 3.1.3

unknown

The MainWP Dashboard &ndash; The WordPress Manager for Professional Website Maintenance WordPress plugin was affected by an Unauthenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.1.3
Fixed in:
3.1.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database