CVE-2025-66131
WordPress Yaad Sarig Payment Gateway For WC plugin <= 2.2.11 - Broken Access Control vulnerability
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yaad Sarig Payment Gateway For WC: from n/a through <= 2.2.11.
| CWE | CWE-862 |
| Vendor | yaadsarig |
| Product | yaad sarig payment gateway for wc |
| Published | Dec 16, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for yaadsarig yaad sarig payment gateway for wc
Be the first to know when new critical vulnerabilities affecting yaadsarig yaad sarig payment gateway for wc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
yaadsarig / Yaad Sarig Payment Gateway For WC
0 โค 2.2.11
References
Credits
Nabil Irawan | Patchstack Bug Bounty Program