CVE-2026-85010 Details
Description
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
A vulnerability exists in the RestroPress WordPress plugin in versions prior to 3.4.6, where the plugin fails to validate client-supplied item add-on prices on the server side. This flaw allows unauthenticated users to set arbitrary prices when items are added to or updated in the cart. As a result, attackers can manipulate the total amount of an order, including reducing it to zero.
Users are advised to update the RestroPress WordPress plugin to version 3.4.6 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/3ebcb11a-9f8c-48e3-8b1f-f91bb2518c34/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| RestroPress | < 3.4.6 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion