GHSA-gw8v-vjq2-rf32MediumCVSS 5.3

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check...

Published
August 19, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.

🔗 References (3)