๐Ÿ” CVE Alert

CVE-2026-85010

MEDIUM 5.3

RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.

Vendor unknown
Product restropress
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown restropress

Be the first to know when new medium vulnerabilities affecting unknown restropress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / RestroPress
0 < 3.4.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3ebcb11a-9f8c-48e3-8b1f-f91bb2518c34/

Credits

Usama Arshad WPScan