Impact
The YayPricing WordPress plugin version before 3.5.7 contains a REST route that allows users with the subscriber role or higher to submit pricing rule data. The implementation does not perform an authorization check on this route, allowing arbitrary JavaScript to be stored. When an administrator later opens the plugin’s settings page, the stored script is rendered in the admin’s browser, resulting in a stored cross‑site scripting attack.
Affected Systems
All WordPress sites running YayPricing versions. The flaw can be exploited on any site that has the plugin installed and has not applied the 3.5.7 or later release.
Risk and Exploitability
This vulnerability has a CVSS score of 8, indicating high severity. The EPSS score is reported as less than 1%, showing a low but non‑zero likelihood of exploitation in the broader ecosystem. It is not listed in the CISA KEV catalog. The attack requires only a subscriber‑level user to create the payload through the exposed REST endpoint, and the payload is delivered without further interaction once an administrator visits the plugin’s settings page. The likely attack vector is over HTTP/HTTPS via the REST API exposed by the plugin.
OpenCVE Enrichment