PatchSiren

YayPricing CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review YayPricing CVE published 2026-08-05

CVE-2026-15230

The YayPricing WordPress plugin before version 3.5.7 is vulnerable due to insufficient capability checks on its REST API routes. This allows any authenticated user, including subscribers, to overwrite the store's pricing configuration and disclose private coupon codes. Users should review their current version and update to 3.5.7 or later to mitigate this risk. Additionally, site administrators should mon [truncated]