Code Injection Vulnerability in YayCurrency by YayCommerce
CVE-2025-60114

6.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 September 2025

What is CVE-2025-60114?

The YayCurrency plugin by YayCommerce has a vulnerability that allows unauthorized code execution through improper control of code generation. Versions from n/a up to 3.2 are affected, posing risks of remote code execution which could compromise site integrity. It is crucial for users of the plugin to upgrade promptly and secure their WordPress environments against potential exploits.

Affected Version(s)

YayCurrency 0 <= 3.3.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.