Junglewise Threat Intelligence

CVE-2026-87888: YayPricing stored XSS via REST API authorization bypass

CVE-2026-87888 · Severity: high · CVSS 8 · Published 2026-09-12

Executive brief

YayPricing is a WordPress plugin for managing dynamic pricing rules. The plugin fails to properly verify user permissions on a REST API endpoint used to save pricing settings, allowing low-privileged users (subscribers and above) to inject malicious JavaScript code that executes when administrators access the plugin's settings page. This can lead to unauthorized administrative actions or credential theft.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw caused by missing authorization checks on the save_page_data REST route. Users with the subscriber role or higher can submit arbitrary JavaScript payloads that are stored in the plugin's pricing rules without sanitization or validation. When an administrator opens the YayPricing settings page, the stored JavaScript executes in their browser with full administrative privileges. The attack requires a valid WordPress user account but no special access to the REST API itself. The vulnerability was fixed in version 3.5.7.

Affected products

  • YayPricing YayPricing before 3.5.7

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Fixed in version 3.5.7

References