VYPR
Medium severity6.6NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60114

CVE-2025-60114

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Code injection vulnerability in YayCurrency WordPress plugin allows remote code execution, enabling attackers to take over websites running versions ≤3.3.1.

CVE-2025-60114 is a code injection vulnerability in the YayCurrency plugin for WordPress, affecting versions up to and including 3.3.1. The plugin fails to properly control the generation of code, allowing an attacker to inject arbitrary code [1].

The vulnerability can be exploited remotely without authentication, making it accessible to any unauthenticated visitor. Attackers can send crafted requests to inject malicious code, which is then executed on the server. This type of vulnerability is actively used in mass-exploit campaigns targeting thousands of WordPress sites [1].

Successful exploitation allows an attacker to execute arbitrary commands on the underlying server. This can lead to backdoor installation, data theft, and complete compromise of the WordPress site. The CVSS score of 6.6 reflects the medium severity, but the real-world impact is significant due to the ease of exploitation and availability of exploit scripts [1].

The vendor has released a patched version. Users are strongly advised to update YayCurrency to the latest version immediately. If updating is not possible, site administrators should contact their hosting provider for assistance. The vulnerability is listed on Patchstack and is known to be exploited in the wild [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.