The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-12 06:16
Updated : 2026-09-14 21:10
NVD link : CVE-2026-87888
Mitre link : CVE-2026-87888
CVE.ORG link : CVE-2026-87888
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
