Beveiligingsadvies

CVE-2026-87888

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-12 06:00:12
Laatst bijgewerkt 2026-09-12 15:29:41
Toegewezen door WPScan
CVSS-score 8.0
Status PUBLISHED

Beschrijving

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.