Critical Authentication Bypass Vulnerability in MyHome Core WordPress Plugin
A critical authentication bypass vulnerability (CVE-2026-15980) with a CVSS score of 9.8 affects the MyHome Core plugin for WordPress, allowing unauthenticated attackers to generate activation tokens and obtain valid authentication cookies for unconfirmed user accounts, including administrators. This vulnerability exists in all versions up to and including 4.4.5 and requires specific configuration settings to be exploitable. Immediate patching is recommended to prevent potential exploitation.