CVE-2026-85010 - RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
CVE ID :CVE-2026-85010
Published : Sept. 21, 2026, 9:17 a.m. | 1 hour, 52 minutes ago
Description :The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 21, 2026, 9:17 a.m. | 1 hour, 52 minutes ago
Description :The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...