Beveiligingsadvies

CVE-2026-78137

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 06:00:19
Laatst bijgewerkt 2026-08-27 14:23:46
Toegewezen door WPScan
CVSS-score 7.5
Status PUBLISHED

Beschrijving

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.