Impact
The vulnerability is a broken access control flaw (CWE-862) in the YayCommerce YayPricing plugin, version 3.5.6 and earlier. It allows a user lacking subscription privileges to access or modify subscriber-only features. This flaw can lead to unauthorized data exposure or configuration changes that compromise confidentiality and integrity for resources intended for subscribed users.
Affected Systems
The flaw applies to WordPress sites running the YayCommerce YayPricing plugin up to and including version 3.5.6. Any installation of these plugin releases is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability falls in the medium severity range. The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is also not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote via HTTP requests to the plugin’s endpoints, and that an attacker may need to be authenticated or have some form of site access to abuse the broken access control, although unauthenticated exploitation is also plausible depending on site configuration.
OpenCVE Enrichment