CVE-2026-87888 - YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route
CVE ID :CVE-2026-87888
Published : Sept. 12, 2026, 6:16 a.m. | 4 hours, 50 minutes ago
Description :The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2026, 6:16 a.m. | 4 hours, 50 minutes ago
Description :The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...