The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Mon, 21 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero. | |
| Title | RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-21T08:51:51.209Z
Reserved: 2026-09-02T18:44:51.359Z
Link: CVE-2026-85010
No data.
Status : Received
Published: 2026-09-21T09:17:05.920
Modified: 2026-09-21T09:17:05.920
Link: CVE-2026-85010
No data.
OpenCVE Enrichment
Updated: 2026-09-21T10:30:09Z
Weaknesses