The plugin is vulnerable to an authentication bypass that allows an unauthenticated user to login as an administrator without providing a password. This vulnerability is only exploitable when the plugin has not been connected to a MainWP Dashboard and the "Require unique security ID" option is not enabled (it is disabled by default).
id: CVE-2024-10783
info:
name: WordPress Plugin MainWP Child - Authentication Bypass
author: Se
...