The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The YayPricing WordPress plugin before version 3.5.7 contains a critical authorization flaw where REST API endpoints fail to validate user capabilities, instead relying solely on nonce validation. This allows any authenticated user—including low-privilege accounts like subscribers—to modify store pricing configurations and access sensitive coupon codes. The vulnerability affects e-commerce sites using this plugin, potentially resulting in revenue loss through unauthorized pricing changes, competitive disadvantage through coupon disclosure, and data exposure of promotional strategies.
While this CVE doesn't map directly to MITRE ATT&CK techniques, Casky's 754 security skills enable practitioners to identify the underlying attack patterns through Claude AI's extended reasoning capabilities. Security teams would recognize this as a privilege escalation and sensitive data exposure risk by monitoring for: unauthorized REST API modifications from low-privilege accounts, unexpected pricing configuration changes without administrative action, and access patterns to coupon endpoints from non-administrative users. Practitioners using Casky would receive findings highlighting improper access control implementations (CWE-284) and recommendations to audit plugin capability checks, implement proper role-based access controls on API routes, and enforce capability verification independent of nonce tokens.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15230. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation