CVE-2026-85010: RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RestroPress WordPress pluginto a version that resolves this vulnerability.Fixed in 3.4.6
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated user can exploit it remotely. No account, special privileges, or user interaction is required.
What does an attacker need to manipulate?
The attacker needs to supply a chosen price for an item add-on while adding an item to the cart or updating the cart. The plugin does not validate that client-supplied add-on price on the server side.
What is the practical impact on orders?
An attacker can place orders with an attacker-chosen total, including a total of zero. The issue affects order pricing rather than confidentiality or availability.
Which versions are affected?
RestroPress versions before 3.4.6 are affected. Updating to version 3.4.6 or later addresses the affected version range described.