SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-87888

HIGH · CVSS 8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The YayPricing WordPress plugin prior to version 3.5.7 is vulnerable due to a lack of authorization checks on a REST route, enabling users with subscriber roles and higher to inject malicious JavaScript. This script executes in the browser of any administrator accessing the plugin's settings page, potentially leading to unauthorized actions or data exposure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-87888
Severity
HIGH
CVSS
8
EPSS
0.23%
WordPress Java

Original NVD Description

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.