GHSA-rhmm-6m6v-j5v4HighCVSS 8.1

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of...

Published
August 5, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.

🔗 References (3)