← WordPress Vulnerabilities
WordPress security by component

YayPricing

YayPricing is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: yaypricing

CVE-2026-66442: YayPricing subscribers can reach a privileged operation

YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version3.5.7
Safe version
Jul 27, 2026 CVE-2026-66442
YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
3.5.7
CVE5.4
NVDPending
Dec 18, 2025 CVE-2025-60077
YayPricing: A security weakness
YayPricing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending