WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites

MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.

8Reported vulnerabilities
9.8Highest CVSS score
6.1.6Latest version
700,000+Active installs

What to do now

Update MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites to 6.1.2 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24877 High 7.2 1.2% Before 4.1.8 4.1.8 November 23, 2021
WF-84019c69-32fd-4331-95d7-53ea1aaff616 Critical 9.8 Before 2.0.9.2 2.0.9.2 March 9, 2015
CVE-2024-10783 High 8.1 2.4% 0 to 5.3.3 (inclusive) 5.3.4 December 13, 2024
WF-f83f878d-b708-4677-929a-e1ced535d99f High 8.3 Before 3.4.5 3.4.5 February 18, 2018
CVE-2023-3132 High 7.5 0.7% 4.4.1.1 and earlier 4.4.1.2 June 27, 2023
WF-71d63f0d-ce01-489e-bcc4-7632f1a4bb04 High 7.3 2.0.22 and earlier 2.0.23 August 7, 2015
WF-a5a34838-fdc5-4954-9576-abf81cbaac2e Medium 6.1 2.0.27 and earlier 2.0.28 September 7, 2015
CVE-2026-27366 Medium 5.3 0.3% 6.1.1 and earlier 6.1.2 June 23, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.