CVE-2025-3530
WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Product Price Manipulation
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a security hash against price tampering while using 'wspsc_product' to display the product, allowing an unauthenticated attacker to substitute details from a cheaper product and bypass payment for a more expensive item.
| CWE | CWE-472 |
| Vendor | mra13 |
| Product | simple shopping cart |
| Published | Apr 23, 2025 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for mra13 simple shopping cart
Be the first to know when new high vulnerabilities affecting mra13 simple shopping cart are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
mra13 / Simple Shopping Cart
0 โค 5.1.2
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/e0a3910b-adc4-4633-a6a1-32ba50894be4?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L171 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L156 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L165 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-simple-paypal-shopping-cart/tags/5.1.2/wp_shopping_cart.php#L261 tipsandtricks-hq.com: https://www.tipsandtricks-hq.com/wordpress-simple-paypal-shopping-cart-plugin-768 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3275373/
Credits
Jack Taylor