Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-15230

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Aug 05, 2026
Vendor unknown

Description

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.

References