PT-2026-83520 · WordPress · Myhome Core

·

CVE-2026-15980

·

Published

2026-08-30

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MyHome Core versions prior to 4.4.6
Description An authentication bypass exists in the MyHome Core plugin for WordPress. The issue stems from missing authorization in the send link() AJAX handler and improper token validation within the activate() function. These flaws allow an unauthenticated attacker to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie, potentially granting administrative access. Exploitation is possible when the MyHome theme is configured in legacy/WPBakery mode with frontend registration and confirmation emails enabled, provided the target account does not have the myhome agent confirmed user meta set.
Recommendations Update MyHome Core to a version newer than 4.4.5. As a temporary mitigation, disable frontend registration. Restrict access to the send link() AJAX handler and the activate() function until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15980

Affected Products

Myhome Core