CVE-2025-3530: WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Product Price Manipulation
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'producttmptwo' for computing a security hash against price tampering while using 'wspscproduct' to display the product, allowing an unauthenticated attacker to substitute details from a cheaper product and bypass payment for a more expensive item.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3530?
CVE-2025-3530 is a medium severity vulnerability that allows product price manipulation in the affected plugin.
How do I fix CVE-2025-3530?
To fix CVE-2025-3530, update the WordPress Simple Shopping Cart plugin to version 5.1.3 or later.
What versions are affected by CVE-2025-3530?
CVE-2025-3530 affects all versions of the WordPress Simple Shopping Cart plugin up to and including 5.1.2.
What is the impact of CVE-2025-3530?
The impact of CVE-2025-3530 is that attackers can manipulate product prices when adding items to their cart.
Is there a workaround for CVE-2025-3530?
A potential workaround for CVE-2025-3530 is to disable the plugin until it can be updated to a secure version.