The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a product to a negative number, which subtracts the product cost from the total order cost. The attack will only work with Manual Checkout mode, as PayPal and Stripe will not process payments for a negative quantity.
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tipsandtricks-hq
Tipsandtricks-hq wordpress Simple Paypal Shopping Cart |
|
| CPEs | cpe:2.3:a:tipsandtricks-hq:wordpress_simple_paypal_shopping_cart:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Tipsandtricks-hq
Tipsandtricks-hq wordpress Simple Paypal Shopping Cart |
Thu, 01 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 May 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a product to a negative number, which subtracts the product cost from the total order cost. The attack will only work with Manual Checkout mode, as PayPal and Stripe will not process payments for a negative quantity. | |
| Title | WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity' | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-01T11:11:41.530Z
Updated: 2025-05-01T13:49:29.539Z
Reserved: 2025-04-22T23:10:04.442Z
Link: CVE-2025-3889
Updated: 2025-05-01T13:49:23.767Z
Status : Analyzed
Published: 2025-05-01T12:15:17.630
Modified: 2025-05-06T15:39:43.323
Link: CVE-2025-3889
No data.