← All CVEs NewScan detects
medium

CVE-2026-85010

RestroPress client-side add-on price trusted by the server - unauthenticated order-total manipulation

Severity
medium
Affected product
restropress
Affected versions
restropress < 3.4.6
Fixed in
restropress 3.4.6
Added to NewScan
2026-09-21
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints restropress from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-21. Directory slug `restropress` (plugin title 'RestroPress - Online Food Ordering System'), confirmed against api.wordpress.org (current 3.4.7, i.e. past the 3.4.6 fix). The cart add/update path accepts the item add-on PRICE from the client and never revalidates it against the configured product, so an unauthenticated visitor sets their own order total - a business-logic/price-tampering flaw, not an injection. Recorded medium rather than high because the impact is financial loss on the merchant's own store, with no access to data or code execution. No `ge`: the cart handler has trusted the client-supplied price for the whole 3.x line. Version source is the readme.txt `Stable tag:` probe plus the plugin's own ?ver= assets, which RestroPress enqueues on every page with a menu or cart widget. Version-match only: proving it means placing a manipulated order on a live store.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →