What is CVE-2026-15230?
CVE-2026-15230 affects the `YayPricing` WordPress plugin versions prior to 3.5.7. The plugin does not perform capability checks on several REST API routes and relies only on a shared nonce. This allows any authenticated user, such as a `subscriber`, to overwrite the store's pricing configuration and disclose private coupon codes.
Azərbaycanca: CVE-2026-15230 `YayPricing` WordPress plugin-in 3.5.7-dən əvvəlki versiyalarını təsir edir. Plugin bir neçə REST API route-u üçün capability yoxlaması aparmır və yalnız paylaşılan nonce-ə əsaslanır. Bu zəiflik autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, `subscriber`) mağazanın qiymət konfiqurasiyasını dəyişməyə və gizli kupon kodlarını oxumağa imkan verir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What privileged operations does the CVE-2026-15230 vulnerability allow in the YayPricing plugin?
This vulnerability allows any authenticated user, such as a subscriber, to overwrite the store's pricing configuration and disclose private coupon codes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.