MainWP Child Reports <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure via Heartbeat API
medium
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- CVSS:
- 5.3
- Affected:
- up to 2.2.6
- Fixed in:
- 2.3
- Disclosed:
- Apr 7, 2026
CVE-2026-4299 on NVD →
MainWP Child Reports [mainwp-child-reports] < 2.2.1
unknown
[en] The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that c...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 8, 2024
CVE-2024-7492 on NVD →
MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update
high
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can be...
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 7, 2024
CVE-2024-7492 on NVD →
MainWP Child Reports <= 2.1.1 - Cross-Site Request Forgery
medium
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the uninstall() function. This makes it possible for unauthenticated attackers to deactivate the plugin via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2
- Disclosed:
- Apr 26, 2024
CVE-2024-33680 on NVD →
MainWP Child Reports [mainwp-child-reports] < 2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Apr 26, 2024
CVE-2024-33680 on NVD →
MainWP Child Reports [mainwp-child-reports] < 2.0.8
unknown
[en] The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Oct 18, 2021
CVE-2021-24754 on NVD →
MainWP Child Reports <= 2.0.7 - Admin+ SQL Injection
high
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
- CVSS:
- 7.2
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Sep 20, 2021
CVE-2021-24754 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database