Authentication Bypass Vulnerability in MyHome Core Plugin for WordPress
CVE-2026-15980

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 August 2026

What is CVE-2026-15980?

The MyHome Core plugin for WordPress is vulnerable to an authentication bypass due to missing authorization in the send_link() AJAX handler and insufficient token validation in the activate() function. This vulnerability allows unauthenticated attackers to create activation tokens for unconfirmed user accounts, potentially granting access to authentication cookies, including those belonging to administrators. Exploitation requires the MyHome theme to operate in legacy/WPBakery mode with frontend registration and confirmation emails enabled. Additionally, it is crucial that the targeted accounts do not possess the myhome_agent_confirmed user meta.

Affected Version(s)

MyHome Core 0 <= 4.4.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad
.