WordPress Plugin Vulnerabilities

RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons

Description

The plugin does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.

Proof of Concept

Affects Plugins

Fixed in 3.4.6

References

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-16 (about 5 days ago)
Added
2026-09-09 (about 12 days ago)
Last Updated
2026-09-11 (about 10 days ago)

Other