CRITICAL
MyHome
CVE published 2026-08-30
CVE-2026-15980
The MyHome Core plugin for WordPress has a critical vulnerability (CVSS Score: 9.8) allowing unauthenticated attackers to bypass authentication and obtain a valid authentication cookie for an unconfirmed user account, including administrators. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. Successful exploitation requires spec [truncated]