CVE-2025-3530 Details
Description
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a security hash against price tampering while using 'wspsc_product' to display the product, allowing an unauthenticated attacker to substitute details from a cheaper product and bypass payment for a more expensive item.
A vulnerability exists in the WordPress Simple Shopping Cart plugin, affecting all versions up to and including 5.1.2. The issue allows for product price manipulation due to a logic flaw in how parameters are used during the cart addition process. The plugin relies on the 'product_tmp_two' parameter to compute a security hash against price tampering, while the 'wspsc_product' parameter is used to display the product. This inconsistency enables an unauthenticated attacker to replace product details with those from a cheaper item, effectively bypassing payment for a more expensive one.
Users can update to WordPress Simple Shopping Cart version 5.1.3, which addresses this vulnerability by improving the price validation process and adding a dynamic product feature to protect download file URLs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2025CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WordPress Simple Shopping Cart | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2025 | New CVE Received | [email protected] |
Volerion