What the vulnerability does
01Description
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.
Explanation of Vulnerability in Simple Terms
02Summary
MainWP Dashboard versions up to 4.5.1.2 contain an improper input validation flaw that allows high-privileged users to modify data integrity. The vulnerability requires network access and high administrative privileges to exploit. An attacker with admin-level access can alter site data, though the impact is limited to integrity and does not affect confidentiality or availability.
What an attacker can do
03Attacker Capabilities
Modify site data through improper input validation.
Potential impact on your site
04Site Impact
A malicious admin or compromised admin account could alter MainWP configuration or managed site data.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the MainWP Dashboard.
Key dates
06Disclosure timeline
November 22, 2023
CVE published
April 8, 2026
Record updated