CVE-2026-85010
5.3 MEDIUMPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated users to manipulate item prices in the RestroPress WordPress plugin, potentially placing orders with arbitrary totals or zero value.
- Exploitability
- Exploitation is relatively easy as it requires no authentication and can be done by any user with access to the affected plugin's functionality.
- Blast radius
- If exploited, this could lead to significant financial loss through fraudulent orders or unauthorized price setting in a restaurant or food service business using the plugin.
- Prioritized remediation
- Update to RestroPress version 3.4.6 or later to validate client-supplied prices on the server side.
auth-bypassprice-misconfigurationweb
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-472
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-10050PoC
- MEDIUMCVE-2026-14465
- HIGHCVE-2026-14553
- MEDIUMCVE-2026-14816
- HIGHCVE-2026-15230
- HIGHCVE-2026-15372
- HIGHCVE-2026-15573
Related by shared AI tags and CWE weakness class. Browse the full archive.