CVE-2026-79410: Webkul Bagisto vulnerability
Published Sep 15, 2026
·Updated
Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.
Affected Software
1 affected component
Webkul Bagisto=2.4.9
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated to exploit the vulnerable add-to-cart path. The issue affects attempts to purchase shippable goods.
2
What is the practical impact of successful exploitation?
An authenticated attacker can manipulate the quantity parameter so that an order total is reduced below the legitimate price of the goods.
3
Which version is identified as affected?
The provided information identifies Webkul Bagisto v2.4.9.