Broken Access Control Vulnerability in YayPricing Plugin by YayCommerce
CVE-2026-66442
5.4MEDIUM
What is CVE-2026-66442?
The YayPricing plugin by YayCommerce is subject to a broken access control vulnerability in versions up to 3.5.6. This weakness allows unauthorized users to gain access to restricted functionalities, potentially compromising sensitive data and operations across websites utilizing the affected plugin. Implementing the latest updates and security patches is essential for maintaining the integrity and security of web applications employing this plugin.
Affected Version(s)
YayPricing <= 3.5.6