Review
YayPricing
CVE published 2026-08-05
CVE-2026-15230
The YayPricing WordPress plugin before version 3.5.7 is vulnerable due to insufficient capability checks on its REST API routes. This allows any authenticated user, including subscribers, to overwrite the store's pricing configuration and disclose private coupon codes. Users should review their current version and update to 3.5.7 or later to mitigate this risk. Additionally, site administrators should mon [truncated]