VYPR

Yaycurrency

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-67994HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.

  • CVE-2025-60114MedSep 26, 2025
    risk 0.43cvss 6.6epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1.

  • CVE-2026-16058Aug 19, 2026
    risk 0.00cvss epss

    The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance…