CVE-2026-85010
RestroPress client-side add-on price trusted by the server - unauthenticated order-total manipulation
- Severity
- medium
- Affected product
- restropress
- Affected versions
- restropress < 3.4.6
- Fixed in
- restropress 3.4.6
- Added to NewScan
- 2026-09-21
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints restropress from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-21. Directory slug `restropress` (plugin title 'RestroPress - Online Food Ordering System'), confirmed against api.wordpress.org (current 3.4.7, i.e. past the 3.4.6 fix). The cart add/update path accepts the item add-on PRICE from the client and never revalidates it against the configured product, so an unauthenticated visitor sets their own order total - a business-logic/price-tampering flaw, not an injection. Recorded medium rather than high because the impact is financial loss on the merchant's own store, with no access to data or code execution. No `ge`: the cart handler has trusted the client-supplied price for the whole 3.x line. Version source is the readme.txt `Stable tag:` probe plus the plugin's own ?ver= assets, which RestroPress enqueues on every page with a menu or cart widget. Version-match only: proving it means placing a manipulated order on a live store.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →