PT-2026-83520 · WordPress · Myhome Core
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyHome Core versions prior to 4.4.6
Description
An authentication bypass exists in the MyHome Core plugin for WordPress. The issue stems from missing authorization in the
send link() AJAX handler and improper token validation within the activate() function. These flaws allow an unauthenticated attacker to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie, potentially granting administrative access. Exploitation is possible when the MyHome theme is configured in legacy/WPBakery mode with frontend registration and confirmation emails enabled, provided the target account does not have the myhome agent confirmed user meta set.Recommendations
Update MyHome Core to a version newer than 4.4.5.
As a temporary mitigation, disable frontend registration.
Restrict access to the
send link() AJAX handler and the activate() function until the update is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myhome Core