CVE-2026-15230: YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/YayPricingto a version that resolves this vulnerability.Fixed in 3.5.7 - Operational
Ensure the YayPricing plugin is updated so versions earlier than 3.5.7 (i.e., any installed YayPricing < 3.5.7) are remediated, as those versions allow authenticated users (e.g., subscribers) to overwrite store pricing configuration and disclose private coupon codes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15230?
CVE-2026-15230 has a risk rating of 57, indicating a medium-level vulnerability.
How do I fix CVE-2026-15230?
To fix CVE-2026-15230, upgrade the YayPricing WordPress plugin to version 3.5.7 or later.
What does CVE-2026-15230 allow an attacker to do?
CVE-2026-15230 allows authenticated users, such as subscribers, to modify pricing configurations and disclose private coupon codes.
Which versions of YayPricing are affected by CVE-2026-15230?
CVE-2026-15230 affects all versions of YayPricing prior to 3.5.7.
What type of attack does CVE-2026-15230 exploit?
CVE-2026-15230 exploits insufficient capability checks on REST API routes in the YayPricing plugin.