VYPR
Medium severity5.3NVD Advisory· Published May 26, 2026

CVE-2026-39655

CVE-2026-39655

Description

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Mayosis Core: from n/a through 5.4.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Mayosis Core plugin versions up to 5.4.7 have a missing authorization vulnerability that allows unprivileged users to execute higher privileged actions.

Vulnerability

The Mayosis Core plugin for WordPress versions from n/a through 5.4.7 contains a missing authorization vulnerability. The issue is classified as a broken access control flaw, meaning the plugin fails to properly verify that a user has the required permissions before allowing access to certain functions or data. This affects access control security levels that are incorrectly configured, enabling exploitation of insufficient authorization checks.

Exploitation

An attacker requires a valid WordPress user account at any privilege level, including the lowest (subscriber). The attacker can then craft requests to the vulnerable endpoints or functions that lack proper authorization checks, such as missing nonce tokens or capability verifications. No elevated permissions are needed; the attacker simply sends a malicious HTTP request to invoke a restricted action.

Impact

Successful exploitation allows an unprivileged user to perform actions or access data that should be reserved for higher-privileged roles (e.g., authors, editors, or administrators). The specific impact depends on the missing authorization context but could include modifying settings, accessing private data, or executing other restricted operations. The CVSS v3 base score is 5.3 (Medium), indicating moderate severity.

Mitigation

As of the reference publication date, users should update the Mayosis Core plugin to the latest patched version. The advisory [1] notes that vulnerabilities like this are used in mass-exploit campaigns, so immediate action is recommended. If unable to update, users should ask their hosting provider or web developer for help. No other workarounds are disclosed in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.