PatchSiren

MyHome CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL MyHome CVE published 2026-08-30

CVE-2026-15980

The MyHome Core plugin for WordPress has a critical vulnerability (CVSS Score: 9.8) allowing unauthenticated attackers to bypass authentication and obtain a valid authentication cookie for an unconfirmed user account, including administrators. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. Successful exploitation requires spec [truncated]