---
id: CVE-2026-87888
title: >-
  The YayPricing  WordPress plugin before 3.5.7 does not perform an
  authorization check on a REST route that saves its pricing rules, allowing
  users with the subscriber role and above to store JavaScript that executes in
  the browser of an …
summary: >-
  The YayPricing  WordPress plugin before 3.5.7 does not perform an
  authorization check on a REST route that saves its pricing rules, allowing
  users with the subscriber role and above to store JavaScript that executes in
  the browser of an …
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: YayPricing
affected:
  - YayPricing < 3.5.7
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87888'
references:
  - url: 'https://wpscan.com/vulnerability/19bc425d-2aa3-4b2b-bc66-ac5ea96502e0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00413
epssPercentile: 0.32945
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-12T15:16:15.606528Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

The YayPricing  WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing  WordPress plugin before 3.5.7's settings page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
