Description
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
Published: 2026-07-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw (CWE-862) in the YayCommerce YayPricing plugin, version 3.5.6 and earlier. It allows a user lacking subscription privileges to access or modify subscriber-only features. This flaw can lead to unauthorized data exposure or configuration changes that compromise confidentiality and integrity for resources intended for subscribed users.

Affected Systems

The flaw applies to WordPress sites running the YayCommerce YayPricing plugin up to and including version 3.5.6. Any installation of these plugin releases is potentially vulnerable.

Risk and Exploitability

With a CVSS score of 5.4, the vulnerability falls in the medium severity range. The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is also not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote via HTTP requests to the plugin’s endpoints, and that an attacker may need to be authenticated or have some form of site access to abuse the broken access control, although unauthenticated exploitation is also plausible depending on site configuration.

Generated by OpenCVE AI on August 4, 2026 at 13:57 UTC.

Remediation

Vendor Solution

Update the WordPress YayPricing Plugin to the latest available version (at least 3.5.7).


OpenCVE Recommended Actions

  • Update the YayPricing plugin to the latest available version (at least 3.5.7).
  • If updating immediately is not possible, restrict or disable subscriber-only functionality in the plugin settings until the patch is applied.
  • Conduct a review of all other WordPress plugins for similar access control weaknesses and apply available updates or enforce hardening measures.

Generated by OpenCVE AI on August 4, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yaycommerce
Yaycommerce yaypricing
Vendors & Products Wordpress
Wordpress wordpress
Yaycommerce
Yaycommerce yaypricing

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
Title WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Yaycommerce Yaypricing
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:06:36.751Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66442

cve-icon Vulnrichment

Updated: 2026-07-27T16:06:31.359Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:11.443

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-66442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses