Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in the MyHome Core plugin for WordPress, affecting all versions prior to 4.4.5. This issue could allow unauthenticated attackers to bypass authentication and gain access to user accounts, including administrative ones. Successful exploitation depends on specific configurations of the MyHome theme, such as having frontend registration and confirmation emails enabled.
- Unauthenticated attackers can bypass login.
- Affects WordPress sites using the MyHome theme.
- Confirms relevance and potential exposure of your sites.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable WordPress site where the MyHome Core plugin is installed and configured in a specific way. This configuration involves enabling frontend registration and requiring a confirmation email for new accounts, while also using legacy WPBakery mode. If the target user account has not yet been confirmed, the attacker can bypass authentication and obtain a valid session cookie, potentially gaining administrative access.
- No prior authentication needed.
- Triggered by AJAX calls to specific functions.
- Leads to unauthorized account access.
Live Threat
Current exploitation, exposure, and threat context
When the MyHome Core plugin is configured with specific settings, unauthenticated attackers could bypass authentication. This could allow them to obtain valid authentication cookies for user accounts, including administrative ones.
- Administrative access and user accounts at risk.
- Exploitable via missing authorization and token validation.
- Unauthorized account access and control.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and potentially the infrastructure team managing the WordPress environment are likely responsible for addressing this vulnerability. The first practical step is to identify all instances of the MyHome Core plugin, determine their reachability and business criticality, and confirm the accountable owner for each instance. Remediation planning should then be based on the assessed risk.
- Confirm application and infrastructure ownership.
- Verify plugin reachability and business criticality.
- Plan remediation based on identified risk.