First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YayExtra: from n/a through 1.5.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
YayCommerce | <=1.5.2 | |
WordPress YayExtra | <=1.5.2 |
Update the WordPress YayExtra plugin to the latest available version (at least 1.5.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31415 is classified as a high severity vulnerability due to its potential for unauthorized access.
To fix CVE-2025-31415, update YayExtra to version 1.5.3 or later, which addresses the missing authorization issue.
CVE-2025-31415 is a missing authorization vulnerability that allows exploitation of incorrectly configured access control security levels.
CVE-2025-31415 affects YayExtra versions up to and including 1.5.2.
Users of YayCommerce YayExtra and WordPress YayExtra versions up to 1.5.2 are impacted by CVE-2025-31415.