CVE

CVE-2026-16058 — YayCurrency – WooCommerce Multi-Currency Switcher [yaycurrency] < 3.3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16058 YayCurrency – WooCommerce Multi-Currency Switcher [yaycurrency] < 3.3.5 Authorization Bypass Through User-Controlled Key Unknown < 3.3.5 3.3.5 2026-08-19

CVE-2026-16058

The YayCurrency WordPress plugin, prior to version 3.3.5, fails to enforce proper access controls for certain functions that are accessible to anyone, including those not logged in. As a result, an attacker can obtain sensitive financial information about a store, including order totals, vendor earnings, and transaction histories.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.