Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15230 | 2 Wordpress, Yaycommerce | 2 Wordpress, Yaypricing | 2026-08-07 | 8.1 High |
| The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes. | ||||
| CVE-2026-66442 | 2 Wordpress, Yaycommerce | 2 Wordpress, Yaypricing | 2026-07-27 | 5.4 Medium |
| Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | ||||
Page 1 of 1.