What is CVE-2026-16058?
This vulnerability affects YayCurrency WordPress plugin versions before 3.3.5. Unauthenticated users can access sensitive information such as order totals, vendor earnings, and balance ledgers due to missing capability checks on multi-vendor integration handlers. Upgrade the plugin to version 3.3.5 or later immediately.
Azərbaycanca: Bu boşluq YayCurrency WordPress plaginin 3.3.5-dən əvvəlki versiyalarına təsir edir. Autentifikasiya olunmamış istifadəçilər çoxsatıcılı inteqrasiya idarəediciləri vasitəsilə sifariş məbləğləri, satıcı gəlirləri və balans kitabçası kimi həssas məlumatları oxuya bilir. Plagini dərhal 3.3.5 və ya daha yeni versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of the YayCurrency plugin are affected by this vulnerability?
The CVE-2026-16058 vulnerability affects YayCurrency WordPress plugin versions before 3.3.5.
What sensitive information can unauthenticated users access by exploiting this vulnerability?
Unauthenticated users can access sensitive information such as order totals, vendor earnings, and balance ledgers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.