CVE-2026-39655
Received Received - Intake
BaseFortify

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: Patchstack

Description
Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-05-26
AI Q&A
2026-05-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
teconce mayosis_core to 5.4.7 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability is a Missing Authorization issue leading to Broken Access Control, which can allow unauthorized users to perform higher-privileged actions.

Such access control weaknesses can potentially impact compliance with standards like GDPR and HIPAA, which require strict access controls to protect sensitive data.

However, the provided information does not explicitly state the direct impact on compliance with these regulations.


Can you explain this vulnerability to me?

CVE-2026-39655 is a Broken Access Control vulnerability in the WordPress Mayosis Core Plugin versions 5.4.7 and below. It occurs because of missing authorization, authentication, or nonce token checks, which allows unauthenticated users to perform actions that should require higher privileges.

This means that the plugin incorrectly configures access control security levels, enabling attackers to exploit these weaknesses to bypass restrictions.


How can this vulnerability impact me? :

The vulnerability allows unauthenticated users to perform higher-privileged actions, which can lead to unauthorized changes or access within the affected WordPress site.

However, the risk of exploitation is considered low and the severity is rated as low (CVSS score 5.3). There is no indication of mass exploitation campaigns currently.

Despite the low severity, it is recommended to take immediate action such as updating the plugin or consulting with a hosting provider or web developer to mitigate potential risks.


What immediate steps should I take to mitigate this vulnerability?

Immediate action is recommended to mitigate this vulnerability despite its low severity.

  • Update the Mayosis Core plugin to a version above 5.4.7 once available.
  • Seek assistance from your hosting provider or a web developer to implement proper access control measures.

Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart