{"id":"CVE-2026-85010","title":"The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…","summary":"The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-472"],"product":"RestroPress","affected":["RestroPress < 3.4.6"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:17:32.607","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85010","references":[{"url":"https://wpscan.com/vulnerability/3ebcb11a-9f8c-48e3-8b1f-f91bb2518c34/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T13:57:40.105520Z"},"epss":0.00194,"epssPercentile":0.09351,"ingestedAt":"2026-09-21T09:34:37.179Z","slug":"CVE-2026-85010","body":"## Overview\n\nThe RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}