CVE-2025-67994: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67994 is a Missing Authorization vulnerability in the YayCommerce YayCurrency WordPress plugin that allows unauthenticated attackers to perform arbitrary content deletion. It affects YayCurrency versions up to and including 3.3, with version 3.3.1 containing the fix. The vulnerability was reported by Denver Jackson on November 25, 2025, and published by Patchstack on February 9, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive operations. This allows unauthenticated network-based attackers to invoke privileged plugin functionality — specifically content deletion — without any authentication or elevated privileges. The attack requires no user interaction and has low complexity, making it trivially exploitable over the network (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to delete arbitrary content from affected WordPress sites, including posts, pages, and media files. This poses a significant integrity and availability risk to website operators, as critical site content can be permanently removed without any credentials. While the CVSS score reflects a high confidentiality impact, Patchstack's classification emphasizes the arbitrary content deletion capability as the primary real-world consequence (Patchstack).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it suitable for mass-exploit campaigns targeting thousands of WordPress sites indiscriminately. Patchstack notes that vulnerabilities of this type are commonly used in automated, large-scale attacks regardless of site traffic or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation. No specific threat actor attribution or confirmed in-the-wild exploitation has been reported, and it does not appear in the CISA KEV catalog at this time (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the YayCurrency plugin version 3.3 or earlier using tools like WPScan, Shodan, or by inspecting plugin directories exposed via the target site.
  2. Identify vulnerable endpoint: Locate the plugin's AJAX action or REST API endpoint responsible for content deletion that lacks proper capability checks (e.g., a wp_ajax_nopriv_ handler or unprotected REST route).
  3. Craft unauthenticated request: Send a crafted HTTP POST or GET request to the vulnerable endpoint without any authentication cookies or nonces, including parameters that specify the content (post ID, page ID, or media attachment) to be deleted.
  4. Achieve content deletion: The server processes the request without authorization checks, resulting in the targeted content being permanently deleted from the WordPress database (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or REST API routes associated with the YayCurrency plugin from unknown or automated IP addresses.
  • Logs: WordPress access logs showing repeated requests to YayCurrency plugin endpoints without session cookies or authentication headers; HTTP 200 responses to deletion-related actions from unauthenticated sources.
  • File System / Database: Unexpected disappearance of posts, pages, or media files from the WordPress database; gaps in post IDs or missing attachments not attributable to normal editorial activity.
  • Process: Automated scanning patterns (high request volume, sequential post ID targeting) originating from a single IP or IP range (Patchstack).

Mitigation and workarounds

Update the YayCurrency plugin to version 3.3.1 or later, which contains the fix for this vulnerability. If an immediate update is not possible, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Site administrators should also review recent content for unexpected deletions and audit plugin permissions (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management