CVE-2026-15230 PUBLISHED

YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure

Assigner: WPScan
Reserved: 09.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.

Product Status

Vendor Unknown
Product YayPricing
Versions Default: unaffected
  • affected from 0 to 3.5.7 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE