CVE-2025-67994
Published: 20 February 2026
Summary
CVE-2025-67994 is a high-severity Missing Authorization (CWE-862) vulnerability. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 13.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2025-67994 is a missing authorization vulnerability (CWE-862) in the YayCurrency WordPress plugin developed by YayCommerce. The flaw allows exploitation of incorrectly configured access control security levels and affects all versions of the plugin from n/a through 3.3 inclusive. Published on 2026-02-20, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating high severity due to its network accessibility and integrity impact.
Unauthenticated attackers (PR:N) can exploit this vulnerability over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N) required. Exploitation enables arbitrary content deletion, compromising the integrity (I:H) of affected WordPress sites while leaving confidentiality and availability unscathed (C:N/A:N).
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/yaycurrency/vulnerability/wordpress-yaycurrency-plugin-3-3-arbitrary-content-deletion-vulnerability?_s_id=cve details this arbitrary content deletion vulnerability in YayCurrency version 3.3.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-208056
Vulnerability details
Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Missing authorization flaw in public-facing WordPress plugin directly enables remote unauthenticated exploitation of the web application.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Enforces approved authorizations for logical access, directly preventing unauthenticated exploitation of the missing authorization flaw allowing arbitrary content deletion.
Identifies and remediates the specific flaw in YayCurrency versions through <=3.3 by applying timely patches to restore proper authorization checks.
Employs least privilege to restrict unnecessary access rights, mitigating impacts from incorrectly configured access control security levels in the plugin.