PT-2024-16542 · Mainwp · Mainwp Dashboard+1
Sean Murphy
+2
·
Published
2024-12-13
·
Updated
2024-12-17
·
CVE-2024-10783
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MainWP Child plugin versions prior to 5.3
Description
The MainWP Child plugin for WordPress is vulnerable to privilege escalation due to a missing authorization check on the
register site function when a site is left in an unconfigured state. This makes it possible for unauthenticated attackers to log in as an administrator on instances where MainWP Child is not yet connected to the MainWP Dashboard. The vulnerability only affects sites that have MainWP Child installed, have not yet connected to the MainWP Dashboard, and do not have the unique security ID feature enabled.Recommendations
For versions prior to 5.2: Update to version 5.3 to fully resolve the issue.
For version 5.2.1: Although a partial patch is included, it is recommended to update to version 5.3 for the complete patch.
As a temporary workaround, consider disabling the
register site function until a patch is available. Restrict access to the MainWP Child plugin to minimize the risk of exploitation. Avoid using the plugin in an unconfigured state until the issue is resolved.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mainwp Child
Mainwp Dashboard