CVE-2026-15230
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 05, 2026
Vendor
unknown
Description
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.