WordPress security by component
YayPricing
Plugin description
YayPricing is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
yaypricingLatest vulnerability
CVE-2026-66442: YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66442
YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
|
3.5.7 |
CVE5.4
NVDPending
|
| Dec 18, 2025 |
CVE-2025-60077
YayPricing: A security weakness
YayPricing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|