Junglewise Threat Intelligence

CVE-2026-15980: MyHome Core authentication bypass in AJAX handler

CVE-2026-15980 · Severity: critical · CVSS 9.8 · Published 2026-08-30

Technologies: MyHome Core.

Executive brief

The MyHome Core WordPress plugin contains an authentication bypass vulnerability allowing unauthenticated attackers to generate activation tokens and obtain valid login credentials for any user account, including administrators. This bypasses the normal account confirmation process and could enable account takeover or unauthorized administrative access if the theme is configured with frontend registration and confirmation emails enabled.

Technical details

The vulnerability exists in the send_link() AJAX handler, which lacks proper authorization checks, and the activate() function, which performs improper token validation. An unauthenticated attacker can exploit missing validation in these functions to generate a valid activation token for an unconfirmed user account and subsequently obtain an authenticated session cookie. Exploitation requires the MyHome theme to be configured in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must not already have the myhome_agent_confirmed user meta set. An attacker can achieve full account takeover, including administrator access if targeted against an admin account.

Affected products

  • MyHome Core up to and including 4.4.5

Timeline

  • 2026-08-30: disclosed

References