PT-2026-31079 · WordPress · Mainwp Child Reports
Hunter Jensen
·
Published
2026-04-08
·
Updated
2026-04-13
·
CVE-2026-4299
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MainWP Child Reports versions up to and including 2.2.6
Description
The MainWP Child Reports plugin for WordPress has a missing authorization check in the
heartbeat received() function within the Live Update class. This allows authenticated attackers with Subscriber-level access or higher to retrieve MainWP Child Reports activity log entries, including action summaries, user information, IP addresses, and contextual data, through the WordPress Heartbeat API by sending a crafted heartbeat request with the wp-mainwp-stream-heartbeat data key.Recommendations
Update MainWP Child Reports to a version later than 2.2.6.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mainwp Child Reports