{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amyhomemyhome_corewordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:myhome:myhome_core:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15980"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MyHome Core plugin (\u003c= 4.4.5)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe MyHome Core plugin for WordPress contains a critical authentication bypass vulnerability (CVE-2026-15980) affecting all versions up to and including 4.4.5. The vulnerability stems from two primary flaws: missing authorization checks in the send_link() AJAX handler and improper token validation within the activate() function.\u003c/p\u003e\n\u003cp\u003eAttackers can exploit these flaws to generate a valid activation token for an unconfirmed user account and subsequently obtain a valid authentication cookie. This allows an unauthenticated actor to hijack any user account, including those with administrator privileges. The exploitation requires specific configuration: the MyHome theme must be operating in legacy or WPBakery mode with frontend registration and confirmation email functionality enabled. Additionally, the target user account must not have the 'myhome_agent_confirmed' metadata flag set. Because this vulnerability allows for complete site takeover, immediate remediation is required for all affected WordPress instances.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full account takeover, including administrative access. This grants attackers the ability to modify site content, inject malicious scripts, install additional backdoors, or exfiltrate sensitive data from the WordPress database. The scope includes any WordPress environment using the MyHome theme configured for frontend registration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the MyHome Core plugin to the latest available version beyond 4.4.5 immediately to resolve CVE-2026-15980.\u003c/li\u003e\n\u003cli\u003eDisable frontend registration or the confirmation email feature in the MyHome theme settings if updating is not immediately feasible.\u003c/li\u003e\n\u003cli\u003eAudit user accounts for unauthorized sessions or unexpected changes in user metadata, specifically checking for the presence of the 'myhome_agent_confirmed' key.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for site administration and monitor web server logs for suspicious POST requests targeting /wp-admin/admin-ajax.php related to the MyHome theme's AJAX handlers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-30T07:08:53Z","date_published":"2026-08-30T07:08:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-myhome-auth-bypass/","summary":"The MyHome Core plugin for WordPress is vulnerable to authentication bypass via insecure AJAX handlers, allowing unauthenticated attackers to hijack arbitrary user accounts.","title":"Authentication Bypass in MyHome Core Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-myhome-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:myhome:myhome_core:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}