# CVE-2026-87888

## Summary

- **CVE ID:** CVE-2026-87888
- **Severity:** HIGH
- **CVSS Score:** 8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The YayPricing  WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing  WordPress plugin before 3.5.7's settings page.

## Affected Products

- Unknown — YayPricing (0)

## References

- [CNA](https://wpscan.com/vulnerability/19bc425d-2aa3-4b2b-bc66-ac5ea96502e0/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._