Impact
The YayCurrency WordPress plugin exposes sensitive financial data because it does not enforce capability checks on several handlers used by its multi‑vendor integration. An unauthenticated user who can iterate identifiers can view order totals, vendor earnings, balance ledgers, and withdrawal histories. This results in ownership or privilege‑misuse weaknesses (CWE‑639) that compromise confidentiality.
Affected Systems
WordPress sites running YayCurrency plugin versions earlier than 3.3.5, regardless of the hosting environment, are vulnerable if the Dokan integration is active.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. It is not listed in CISA KEV. Based on the description, the likely attack vector is over the network by issuing HTTP requests to exposed integration endpoints without authentication, allowing attackers to enumerate identifiers and retrieve sensitive data.
OpenCVE Enrichment