cleantalk
Vulnerabilities and Security Researches

YayCurrency – WooCommerce Multi-Currency Switcher, CVE-2025-67994

CVE, Research URL

CVE-2025-67994

Published on
Feb 20, 2026
Research Description
Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.
Affected versions
max 3.3.
Status
vulnerable