← Back to search

CVE-2026-85010

5.3 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated users to manipulate item prices in the RestroPress WordPress plugin, potentially placing orders with arbitrary totals or zero value.
Exploitability
Exploitation is relatively easy as it requires no authentication and can be done by any user with access to the affected plugin's functionality.
Blast radius
If exploited, this could lead to significant financial loss through fraudulent orders or unauthorized price setting in a restaurant or food service business using the plugin.
Prioritized remediation
Update to RestroPress version 3.4.6 or later to validate client-supplied prices on the server side.
auth-bypassprice-misconfigurationweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-472

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.