MainWP Child Reports

MainWP Child Reports has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (50%). Other recurring categories include Missing Authorization, SQL Injection.

Every one of the 4 issues recorded for MainWP Child Reports has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. MainWP Child Reports is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all MainWP Child Reports vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-7492

MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update

Read the full analysis

Vulnerability Records

4 records
MainWP Child Reports banner
Latestv2.3.1

MainWP Child Reports

mainwp

Author

mainwp

4.3(6)
86/100
Last Updated
2026-08-20 (23d ago)
Active Installs
100,000+
Downloads
1,672,580
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2015-08-10 (11y ago)

Note: This plugin requires PHP 7.4 or higher to be activated and is only useful if you are using MainWP and the MainWP Pro Reports Extension. Install the MainWP Child Plugin plugin first. The MainWP Child Report plugin communicates changes on your Child sites to the MainWP Pro Reports Extension in order to create the Pro Reports. Credit to the Stream Plugin which the MainWP Child Reports plugin is built on.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C