Impact
The vulnerability is a Missing Authorization flaw that allows an attacker to delete arbitrary content such as posts, pages, or media items. Because deletion is performed without proper role checks, a user with any authenticated presence can remove valuable data, leading to loss of integrity and potentially to a denial of service if critical content is wiped. The impact is limited to the data available through the plugin and does not provide broader system compromise, but the loss of content can be business‑disruptive and difficult to recover.
Affected Systems
The flaw affects the YayCurrency plugin for WordPress, developed by YayCommerce. Versions from the earliest available through 3.3 are vulnerable; any WordPress installation using the plugin in these versions is at risk.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is categorized as high severity. The EPSS score of < 1% indicates that exploitation is currently considered unlikely, but the presence of the flaw means an attacker who can gain any authenticated session or who can exploit a misconfigured role can execute the deletion without special prerequisites. Since the vulnerability is not listed in CISA’s KEV catalog, no known widespread exploitation activity has been reported. The likely attack vector is remote, via crafted HTTP requests to deletion endpoints that the plugin incorrectly authorizes.
OpenCVE Enrichment