WordPress Plugin Vulnerabilities

StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart

Description

The plugin does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-25 (about 2 days ago)

Other