Executive brief
Mayosis Core is a WordPress plugin used to build membership and community sites. An unauthenticated attacker can inject malicious JavaScript into pages viewed by site visitors, potentially stealing user credentials, hijacking accounts, or compromising sensitive data. The vulnerability requires social engineering (victim clicking a malicious link) but poses a significant risk to any website using the affected plugin.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in WordPress Mayosis Core plugin versions 5.4.7 and earlier. The vulnerability is unauthenticated and requires user interaction—an attacker crafts a malicious link containing JavaScript payload that executes in the victim's browser when clicked. The vulnerability appears to stem from insufficient input validation or output encoding of user-supplied parameters. Successful exploitation allows an attacker to steal session cookies, redirect to phishing pages, or perform actions on behalf of the victim. As of the advisory date, no official patch is available; users are advised to use Patchstack's mitigation rules or upgrade once a patch is released.
Affected products
- Mayosis Core <= 5.4.7
Timeline
- 2026-08-18: disclosed: Published on NVD
- 2026-01-16: other: Initially reported to Patchstack by João Pedro S Alcântara (Kinorth)