{"id":"CVE-2026-15230","published":"2026-08-05T07:16:35.010","lastModified":"2026-08-05T16:16:50.447","description":"The YayPricing  WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/c2346f90-130c-45da-92ca-31acaa2f4605/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows any authenticated user to overwrite pricing configurations and disclose private coupon codes due to missing capability checks in REST API routes.","exploitability":"Exploitation is relatively easy as it requires only an authenticated session, such as that of a subscriber.","blast_radius":"If exploited, the impact could be significant, affecting store pricing and exposing sensitive coupon information.","remediation":"Update to YayPricing WordPress plugin version 3.5.7 or later to apply proper capability checks.","tags":["auth-bypass","web","wp-plugin","config"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:50:12.017Z"}}