← Terug naar overzicht

CVE-2026-15980 describes a critical authentication bypass vulnerability in the MyHome Core plugin for WordPress, affecting all versions up to and including 4.4.5. The flaw stems from missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. Unauthenticated attackers can exploit this to generate activation tokens for unconfirmed user accounts and obtain valid authentication cookies, potentially gaining administrator-level access. Exploitation requires the MyHome theme to be in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must lack the myhome_agent_confirmed user meta flag. This vulnerability poses a significant risk to real estate WordPress sites using this theme. No patch version is explicitly mentioned beyond the affected range of 4.4.5 and below.

Affected products

  • MyHome Core WordPress Plugin (up to 4.4.5)
  • MyHome Real Estate WordPress Theme

Related CVE's

  • CVE-2026-15980

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities