← WordPress Vulnerabilities
WordPress security by component

yaypricing

yaypricing creates dynamic pricing rules, discounts, and offers for WooCommerce products.

yaypricing (yaypricing) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.1.

Plugin slug: yaypricing

CVE-2026-87888: YayPricing lets subscribers store scripts in pricing rules

YayPricing before 3.5.7 exposes a REST route that saves pricing rules without checking authorization. A subscriber can store JavaScript in a rule; it executes in an administrator's browser when the administrator opens the plugin settings page. The authoritative export does not name the route, request field, or output context.

PublishedSep 12, 2026
Known safe version3.5.7
Published vulnerabilities for yaypricing
Safe version
Sep 12, 2026 CVE-2026-87888
YayPricing lets subscribers store scripts in pricing rules
YayPricing before 3.5.7 exposes a REST route that saves pricing rules without checking authorization. A subscriber can store JavaScript in a rule; it executes in an administrator's browser when the administrator opens the plugin settings page. The authoritative export does not name the route, request field, or output context.
3.5.7
CVE8.0
NVDPending
Aug 05, 2026 CVE-2026-15230
YayPricing subscriber REST access permits pricing takeover
YayPricing before 3.5.7 protects several REST routes only with a shared nonce and omits capability checks. Any authenticated user, including a Subscriber who can obtain the nonce, can overwrite the store's pricing configuration and disclose private coupon codes. This unscored record received deeper review because a low-privilege account gains a store-configuration write primitive and sensitive promotion data.
3.5.7
CVE8.1
NVDPending
Jul 27, 2026 CVE-2026-66442
YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check.
3.5.7
CVE5.4
NVDPending
Dec 18, 2025 CVE-2025-60077
YayPricing: A security weakness
YayPricing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending