OVERVIEW CVE-2026-4299 affects the MainWP Child Reports plugin for WordPress in all versions up to and including 2.2.6. The vulnerability involves a missing authorization check in the heartbeat_received() function within the Live_Update class, allowing authenticated subscribers and higher-privileged users to access sensitive activity log data through the WordPress Heartbeat API without proper permission validation. SEVERITY The vulnerability has a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no user interaction and low complexity. The attack requires prior authentication but no special privileges beyond subscriber-level access. The primary impact is confidentiality compromise, as attackers can extract sensitive information including activity log entries, user details, IP addresses, and contextual operational data. Integrity and availability are not affected. EXPLOITATION STATUS Current exploitation appears minimal. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and is not on the Hot List for active exploitation. The EPSS score of 0.00015 indicates very low probability of exploitation in the wild compared to other disclosed vulnerabilities. No publicly available exploit code has been reported, and community attention remains limited at this time. Organizations should still prioritize patching to prevent potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.2.6CPE match | cpe:2.3:a:mainwp:mainwp_child_reports:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.