Executive brief
YayPricing is a WordPress plugin used by online stores to manage dynamic pricing and discounts. A security flaw in versions 3.5.6 and earlier allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. This could potentially allow low-privileged users to interfere with pricing configurations or store operations, though the overall risk is considered moderate.
Technical details
A broken access control vulnerability exists in the YayCommerce YayPricing plugin for WordPress (versions <= 3.5.6) due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw via network requests to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability is addressed in version 3.5.7, which implements proper authorization validation.
Affected products
- YayCommerce YayPricing <= 3.5.6
Timeline
- 2026-07-17: other: Reported by K. Sorrachat
- 2026-07-27: advisory: Advisory published by Patchstack and NVD
- 2026-07-27: patched: Patch released in version 3.5.7