CyberRota Analysis
AI-GeneratedThe YayPricing WordPress plugin prior to version 3.5.7 lacks proper capability checks on its REST API routes, enabling any authenticated user, including subscribers, to modify the store's pricing settings and access private coupon codes. This vulnerability poses a significant risk to site integrity and confidentiality, making it crucial for WordPress site administrators using this plugin to prioritize updates to the latest version.
Original NVD Description
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.