CVE-2026-85010

Published: Set 21, 2026 Last Modified: Set 21, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.

472

External Control of Assumed-Immutable Web Parameter

Draft
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Modify Application Data
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
https://wpscan.com/vulnerability/3ebcb11a-9f8c-48e3-8b1f-f91bb2518c34/