SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78137

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices, enabling unauthenticated attackers to manipulate product pricing during the checkout process, particularly when the BOGO offer feature is active. This could lead to significant financial losses for e-commerce sites using the plugin, as attackers can exploit this flaw to sell products at arbitrary prices. Website administrators and e-commerce operators utilizing this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-78137
Severity
HIGH
CVSS
7.5
EPSS
0.28%
WordPress

Original NVD Description

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.