Junglewise Threat Intelligence

CVE-2026-85010: RestroPress WordPress plugin price manipulation in cart add-ons

CVE-2026-85010 · Severity: medium · CVSS 5.3 · Published 2026-09-21

Executive brief

RestroPress is a WordPress plugin that manages online food ordering and restaurant operations. The plugin fails to validate item add-on prices on the server, allowing attackers to manipulate order totals down to zero without authentication. This enables fraudulent orders and complete bypass of payment collection for restaurant transactions.

Technical details

The vulnerability is a server-side validation bypass in cart add-on price handling. Unauthenticated attackers can manipulate client-supplied prices when adding or updating items in the cart, allowing arbitrary price injection including zero-cost orders. The plugin accepts the attacker-controlled price without server-side verification, enabling price manipulation attacks.

Affected products

  • RestroPress RestroPress before 3.4.6

Timeline

  • 2026-09-16: disclosed
  • 2026-09-21: patched: Fixed in version 3.4.6

References

Related threats