AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15230

HIGH · CVSS 8.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The YayPricing WordPress plugin prior to version 3.5.7 lacks proper capability checks on its REST API routes, enabling any authenticated user, including subscribers, to modify the store's pricing settings and access private coupon codes. This vulnerability poses a significant risk to site integrity and confidentiality, making it crucial for WordPress site administrators using this plugin to prioritize updates to the latest version.

CVE
CVE-2026-15230
Severity
HIGH
CVSS
8.1
EPSS
0.25%
WordPress

Original NVD Description

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.