Description
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
Published: 2026-09-12
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that can be executed by any subscriber or higher user, compromising administrators when they view the plugin's settings page
Action: Upgrade
AI Analysis

Impact

The YayPricing WordPress plugin version before 3.5.7 contains a REST route that allows users with the subscriber role or higher to submit pricing rule data. The implementation does not perform an authorization check on this route, allowing arbitrary JavaScript to be stored. When an administrator later opens the plugin’s settings page, the stored script is rendered in the admin’s browser, resulting in a stored cross‑site scripting attack.

Affected Systems

All WordPress sites running YayPricing versions. The flaw can be exploited on any site that has the plugin installed and has not applied the 3.5.7 or later release.

Risk and Exploitability

This vulnerability has a CVSS score of 8, indicating high severity. The EPSS score is reported as less than 1%, showing a low but non‑zero likelihood of exploitation in the broader ecosystem. It is not listed in the CISA KEV catalog. The attack requires only a subscriber‑level user to create the payload through the exposed REST endpoint, and the payload is delivered without further interaction once an administrator visits the plugin’s settings page. The likely attack vector is over HTTP/HTTPS via the REST API exposed by the plugin.

Generated by OpenCVE AI on September 15, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the YayPricing plugin to version 3.5.7 or later, which removes the missing authorization check on the REST route.
  • Restrict access to the affected REST endpoint by configuring role‑based permissions or firewall rules so that only administrators can access it.
  • If the plugin is not required, remove or deactivate it from the WordPress installation to eliminate the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
Title YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:29:41.359Z

Reserved: 2026-09-09T14:26:35.755Z

Link: CVE-2026-87888

cve-icon Vulnrichment

Updated: 2026-09-12T15:16:11.584Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:27.890

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')