VYPR

Yaypricing

by WordPress

Source repositories

CVEs (4)

  • CVE-2026-15230HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon…

  • CVE-2026-87888HigSep 12, 2026
    risk 0.52cvss 8.0epss 0.00

    The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing …

  • CVE-2025-60077HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in YayCommerce YayPricing yaypricing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects YayPricing: from n/a through <= 3.5.3.

  • CVE-2026-66442MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.