
Reading about client-side data manipulation and landed on a case from 2025. CVE-2025-3530, WordPress Simple PayPal Shopping Cart ≤ 5.1.2. The plugin tried to stop price tampering with a security hash. The hash was computed from product_tmp_two. The product that actually landed in the cart came from wspsc_product. An unauthenticated attacker could supply details from a cheap product for the hash check and an expensive one for the cart, then pay the lower amount
