Mayosis Core <= 5.4.7 - Missing Authorization
medium
The Mayosis Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.4.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.4.7
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2026
CVE-2026-39655 on NVD →
Mayosis Core <= 5.4.1 - Unauthenticated Arbitrary File Read
high
The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Apr 24, 2025
CVE-2025-1565 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database