WordPress Plugin Vulnerabilities
RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
Description
The plugin does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-16 (about 5 days ago)
Added
2026-09-09 (about 12 days ago)
Last Updated
2026-09-11 (about 10 days ago)