WordPress security by component
yaypricing
Plugin description
yaypricing creates dynamic pricing rules, discounts, and offers for WooCommerce products.
yaypricing (yaypricing) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
yaypricingLatest vulnerability
CVE-2026-87888: YayPricing lets subscribers store scripts in pricing rules
YayPricing before 3.5.7 exposes a REST route that saves pricing rules without checking authorization. A subscriber can store JavaScript in a rule; it executes in an administrator's browser when the administrator opens the plugin settings page. The authoritative export does not name the route, request field, or output context.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-87888
YayPricing lets subscribers store scripts in pricing rules
YayPricing before 3.5.7 exposes a REST route that saves pricing rules without checking authorization. A subscriber can store JavaScript in a rule; it executes in an administrator's browser when the administrator opens the plugin settings page. The authoritative export does not name the route, request field, or output context.
|
3.5.7 |
CVE8.0
NVDPending
|
| Aug 05, 2026 |
CVE-2026-15230
YayPricing subscriber REST access permits pricing takeover
YayPricing before 3.5.7 protects several REST routes only with a shared nonce and omits capability checks. Any authenticated user, including a Subscriber who can obtain the nonce, can overwrite the store's pricing configuration and disclose private coupon codes. This unscored record received deeper review because a low-privilege account gains a store-configuration write primitive and sensitive promotion data.
|
3.5.7 |
CVE8.1
NVDPending
|
| Jul 27, 2026 |
CVE-2026-66442
YayPricing subscribers can reach a privileged operation
YayPricing through 3.5.6 lets a Subscriber reach a plugin operation without the required capability or ownership check.
|
3.5.7 |
CVE5.4
NVDPending
|
| Dec 18, 2025 |
CVE-2025-60077
YayPricing: A security weakness
YayPricing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|