Impact
The RestroPress WordPress plugin, prior to version 3.4.6, fails to validate the unit price of item add‑ons on the server side when items are added to or updated in the cart. This allows an attacker who is not logged in to supply an arbitrary price, including zero, and place orders that reflect the attacker‑chosen total. The consequence is financial loss from fraudulent or zero‑value orders and the ability to consume site resources for illegitimate transactions without authorization.
Affected Systems
All installations of the RestroPress plugin with a version lower than 3.4.6, regardless of the WordPress version or hosting environment. The vendor is listed as Unknown:RestroPress in the vendor/product metadata. No specific OS or platform information is provided.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating a medium severity risk. The EPSS score is not available, so the likelihood of exploitation cannot be quantified with that metric, but the absence of a KEV listing suggests it is not known to be actively exploited at a widespread scale. An attacker can trigger the flaw by sending standard HTTP requests to the plugin’s cart endpoints from any location, as authentication is not required for cart manipulation. The attacker only needs to understand the API for add‑ons, which is likely documented in the plugin, making the attack vector straightforward and low‑effort to execute.
OpenCVE Enrichment