Executive brief
Mayosis Core is a WordPress plugin used to power digital marketplaces and creative portfolios. A security flaw in the plugin allows unauthorized individuals to bypass access controls, potentially allowing them to perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes to the website's configuration or content.
Technical details
A missing authorization vulnerability (CWE-862) exists in the TeconceTheme Mayosis Core plugin for WordPress through version 5.4.7. The flaw stems from a failure to implement proper permission checks or nonce validation on certain functions, allowing unauthenticated remote attackers to execute actions that should require higher privileges. According to the CVSS vector, the impact is limited to integrity (I:L), meaning an attacker can modify some data but cannot necessarily view sensitive information or crash the service. As of the advisory date, no official patch has been released.
Affected products
- TeconceTheme Mayosis Core n/a through 5.4.7
Timeline
- 2026-01-16: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-05-26: disclosed: Vulnerability published by Patchstack
- 2026-05-26: advisory: NVD entry created