Security Advisory

CVE-2026-16058

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 06:00:16
Last updated 2026-08-19 13:26:56
Assigner WPScan
CVSS score 5.3
State PUBLISHED

Description

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.