๐Ÿ” CVE Alert

CVE-2026-15230

UNKNOWN 0.0

YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.

Vendor unknown
Product yaypricing
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for unknown yaypricing

Be the first to know when new unknown vulnerabilities affecting unknown yaypricing are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / YayPricing
0 < 3.5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c2346f90-130c-45da-92ca-31acaa2f4605/

Credits

Muni Nitish Kumar Yaddala WPScan