CVE-2025-3530

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a security hash against price tampering while using 'wspsc_product' to display the product, allowing an unauthenticated attacker to substitute details from a cheaper product and bypass payment for a more expensive item.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Full discourse1 post
  • pid1@pid1_

    Reading about client-side data manipulation and landed on a case from 2025. CVE-2025-3530, WordPress Simple PayPal Shopping Cart ≤ 5.1.2. The plugin tried to stop price tampering with a security hash. The hash was computed from product_tmp_two. The product that actually landed in the cart came from wspsc_product. An unauthenticated attacker could supply details from a cheap product for the hash check and an expensive one for the cart, then pay the lower amount

    0000042
    109 followersView on X

Explore more