CVE-2026-78137: StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
StoreGrowth: Smart Sales Booster for WooCommerceto a version that resolves this vulnerability.Fixed in 2.1.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Stores using the StoreGrowth WordPress plugin with a version earlier than 2.1.2 are affected when the BOGO offer feature is enabled. Exploitation does not require authentication.
What does an attacker need to exploit it?
An attacker needs to submit requests to either of the affected unauthenticated add-to-cart actions while supplying a chosen product price. The manipulated price can persist into the checkout total.
What is the immediate mitigation if updating is not possible?
Disable the StoreGrowth BOGO offer feature until the plugin can be updated to version 2.1.2 or later.