MainWP Child Reports
MainWP Child Reports has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (50%). Other recurring categories include Missing Authorization, SQL Injection.
Every one of the 4 issues recorded for MainWP Child Reports has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. MainWP Child Reports is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-7492MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update
Read the full analysisVulnerability Records

MainWP Child Reports
Author
mainwp
Note: This plugin requires PHP 7.4 or higher to be activated and is only useful if you are using MainWP and the MainWP Pro Reports Extension. Install the MainWP Child Plugin plugin first. The MainWP Child Report plugin communicates changes on your Child sites to the MainWP Pro Reports Extension in order to create the Pro Reports. Credit to the Stream Plugin which the MainWP Child Reports plugin is built on.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C