Mainwp provides a WordPress site-management platform and its affiliated extensions, serving administrators who oversee multiple WordPress installations from a centralized dashboard. The platform's recurring vulnerability exposure centers on web-application flaws characteristic of WordPress plugins and dashboards: SQL injection, cross-site request forgery, cross-site scripting, missing authorization checks, and sensitive-information disclosure across its core dashboard, child-site connector, and extension components. A meaningful share of vulnerabilities reach serious severity, and the platform's attack surface—administrative interfaces exposed to the internet or to trusted networks—draws a moderate tendency toward public exploit availability; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mainwp over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27366HIGH Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | Jun 25, 2026 | 7.5 | 32 | NO | NO |
CVE-2016-15041MEDIUM The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_ | Oct 16, 2024 | 6.1 | 31 | NO | YES |
CVE-2023-23645CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Exten | May 17, 2024 | 9.9 | 30 | NO | NO |
CVE-2026-57327MEDIUM Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | Jun 29, 2026 | 6.3 | 29 | NO | NO |
CVE-2023-23659HIGH Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions. | Feb 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-7492HIGH The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce valid | Aug 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-23660HIGH Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions. | Jul 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-23651HIGH Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions. | Oct 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-24877HIGH The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by hi | Nov 23, 2021 | 7.2 | 24 | NO | NO |
CVE-2023-23640HIGH Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6. | Jun 9, 2024 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mainwp.
Media articles that mention a CVE ID that affects a product developed by Mainwp — matched by CVE ID, not by vendor name.