← back
CVE-2026-87888highCWE-79

YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
Unknown · YayPricing
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.