Junglewise Threat Intelligence

CVE-2026-66442: YayCommerce YayPricing broken access control in WordPress plugin

CVE-2026-66442 · Severity: medium · CVSS 5.4 · Published 2026-07-27

Executive brief

YayPricing is a WordPress plugin used by online stores to manage dynamic pricing and discounts. A security flaw in versions 3.5.6 and earlier allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. This could potentially allow low-privileged users to interfere with pricing configurations or store operations, though the overall risk is considered moderate.

Technical details

A broken access control vulnerability exists in the YayCommerce YayPricing plugin for WordPress (versions <= 3.5.6) due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw via network requests to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability is addressed in version 3.5.7, which implements proper authorization validation.

Affected products

  • YayCommerce YayPricing <= 3.5.6

Timeline

  • 2026-07-17: other: Reported by K. Sorrachat
  • 2026-07-27: advisory: Advisory published by Patchstack and NVD
  • 2026-07-27: patched: Patch released in version 3.5.7

References