{"id":"CVE-2026-85010","published":"2026-09-21T09:17:05.920","lastModified":"2026-09-21T15:17:32.607","description":"The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-472"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/3ebcb11a-9f8c-48e3-8b1f-f91bb2518c34/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to manipulate item prices in the RestroPress WordPress plugin, potentially placing orders with arbitrary totals or zero value.","exploitability":"Exploitation is relatively easy as it requires no authentication and can be done by any user with access to the affected plugin's functionality.","blast_radius":"If exploited, this could lead to significant financial loss through fraudulent orders or unauthorized price setting in a restaurant or food service business using the plugin.","remediation":"Update to RestroPress version 3.4.6 or later to validate client-supplied prices on the server side.","tags":["auth-bypass","price-misconfiguration","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:27:18.600Z"}}