9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
AI Analysis
Missing capability check on the `yaymail_import_state` AJAX action allows authenticated attackers to update arbitrary options, potentially leading to privilege escalation.
Basic Information
ID
CVE-2026-1937
Source
Wordfence
Published
Feb 18, 2026 at 06:42
Affected Product
Vendor
yaycommerce
Product
YayMail – WooCommerce Email Customizer
Version
*
Affected Versions
yaycommerce YayMail – WooCommerce Email Customizer *
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
yaycommerce
Product
YayMail – WooCommerce Email Customizer
Version
4.3.2