Impact
The vulnerability lies in missing capability checks on several REST API routes of the YayPricing WordPress plugin. Relying only on a shared nonce, any authenticated user—including subscribers—can overwrite the store’s pricing configuration and expose private coupon codes. This allows an attacker to alter pricing, potentially causing financial loss, and to discover hidden coupon codes that may be used elsewhere to gain unauthorized discounts or access.
Affected Systems
The affected product is the YayPricing WordPress plugin, with any release before version 3.5.7. Any WordPress site running an impacted version of this plugin is vulnerable.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but its impact is significant. An attacker only needs to be authenticated to the site, making exploitation straightforward via the exposed REST API calls. The lack of proper authorization controls makes this a high‑risk issue that can compromise the financial integrity of the site.
OpenCVE Enrichment