Impact
The StoreGrowth WordPress plugin, in versions prior to 2.1.2, fails to validate a browser‑supplied product price on two unauthenticated actions. This allows an attacker to add a product to the cart at any price they choose. When the BOGO offer feature is enabled, the manipulated price is carried through to the checkout total, enabling unauthorized financial loss through unfair discounts.
Affected Systems
Any WordPress site that has installed the StoreGrowth Smart Sales Booster for WooCommerce with a version older than 2.1.2 is affected, regardless of the specific plugin version number, as the flaw exists in all releases before that fix. The vulnerability is tied to the Unknown:StoreGrowth product; no patch or version list from the CNA is available, so any pre‑2.1.2 release counts.
Risk and Exploitability
Because the attack does not require authentication and the vulnerability has a CVSS score of 7.5, the risk is assessed as high from an economic perspective. The EPSS score is < 1%, and the vulnerability is not in the CISA KEV catalog, but the lack of input validation makes exploitation trivial through crafted HTTP requests that set the price parameter. Successful exploitation will reduce revenue by forcing the checkout to reflect the attacker‑supplied price.
OpenCVE Enrichment