CyberRota Analysis
AI-GeneratedThe YayPricing WordPress plugin prior to version 3.5.7 is vulnerable due to a lack of authorization checks on a REST route, enabling users with subscriber roles and higher to inject malicious JavaScript. This script executes in the browser of any administrator accessing the plugin's settings page, potentially leading to unauthorized actions or data exposure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.