yaypricing
yaypricing creates dynamic pricing rules, discounts, and offers for WooCommerce products.
yaypricing (yaypricing) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 8.1.
yaypricingCVE-2026-15230: YayPricing subscriber REST access permits pricing takeover
YayPricing before 3.5.7 protects several REST routes only with a shared nonce and omits capability checks. Any authenticated user, including a Subscriber who can obtain the nonce, can overwrite the store's pricing configuration and disclose private coupon codes. This unscored record received deeper review because a low-privilege account gains a store-configuration write primitive and sensitive promotion data. The CNA does not disclose the route paths, HTTP methods or request fields.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-15230
YayPricing subscriber REST access permits pricing takeover
YayPricing before 3.5.7 protects several REST routes only with a shared nonce and omits capability checks. Any authenticated user, including a Subscriber who can obtain the nonce, can overwrite the store's pricing configuration and disclose private coupon codes. This unscored record received deeper review because a low-privilege account gains a store-configuration write primitive and sensitive promotion data. The CNA does not disclose the route paths, HTTP methods or request fields.
|
3.5.7 |
CVE8.1
NVDPending
|
| Jul 27, 2026 |
CVE-2026-66442
YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
|
3.5.7 |
CVE5.4
NVDPending
|
| Dec 18, 2025 |
CVE-2025-60077
YayPricing: A security weakness
YayPricing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|