CVE-2026-16058
YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.
| Vendor | unknown |
| Product | yaycurrency |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yaycurrency
Be the first to know when new unknown vulnerabilities affecting unknown yaycurrency are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / YayCurrency
0 < 3.3.5
References
Credits
Shivamani Vastrala WPScan