CVE-2026-15980
Received Received - Intake

Authentication Bypass in MyHome Core WordPress Plugin

Vulnerability report for CVE-2026-15980, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: Wordfence

Description

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie for that account, including administrators. Successful exploitation requires the MyHome theme to be configured in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must not already have the myhome_agent_confirmed user meta set.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
myhome core to 4.4.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-289 The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MyHome Core WordPress plugin up to version 4.4.5 has an authentication bypass flaw. Unauthenticated attackers can exploit missing authorization in the send_link() function and weak token validation in activate() to generate activation tokens for unconfirmed accounts. This allows attackers to obtain valid authentication cookies, including for admin accounts, if the MyHome theme is in legacy mode with frontend registration and email confirmation enabled.

Impact Analysis

Attackers could gain full admin access to your WordPress site without credentials. They could take over accounts, modify site content, install malware, steal data, or completely compromise the website. This includes accessing sensitive user information if the site handles such data.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face fines, legal penalties, and reputational damage due to non-compliance if user data is exposed through exploitation.

Mitigation Strategies

Update the MyHome Core plugin to the latest version beyond 4.4.5 immediately. Disable frontend registration and confirmation email features if not required. Check user accounts for the myhome_agent_confirmed meta and remove it if present. Monitor for unauthorized account activations or unusual authentication activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15980. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart