Loading market data...
← Back to CVE feed

CVE-2026-85010

MEDIUM CVSS 5.3 View on NVD ↗

Description

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Sep 21, 2026 09:17 UTC Modified: Sep 21, 2026 15:17 UTC