Authentication Bypass Vulnerability in MyHome Core Plugin for WordPress
CVE-2026-15980
9.8CRITICAL
What is CVE-2026-15980?
The MyHome Core plugin for WordPress is vulnerable to an authentication bypass due to missing authorization in the send_link() AJAX handler and insufficient token validation in the activate() function. This vulnerability allows unauthenticated attackers to create activation tokens for unconfirmed user accounts, potentially granting access to authentication cookies, including those belonging to administrators. Exploitation requires the MyHome theme to operate in legacy/WPBakery mode with frontend registration and confirmation emails enabled. Additionally, it is crucial that the targeted accounts do not possess the myhome_agent_confirmed user meta.
Affected Version(s)
MyHome Core 0 <= 4.4.5