
PEACH
Un cadre d’isolation des locataires
CVE-2026-78137 is an unauthenticated arbitrary price manipulation vulnerability in the StoreGrowth: Smart Sales Booster for WooCommerce WordPress plugin. The flaw allows unauthenticated attackers to add products to the shopping cart at an attacker-chosen price, which carries through to the checkout total when the BOGO (Buy One Get One) offer feature is enabled. It affects all versions of the plugin before 2.1.2 and was publicly disclosed on August 25, 2026, with the CVE published on August 27, 2026. The vulnerability carries a CVSS score of 7.5 (High) and was discovered and reported by researcher Shikhali Jamalzade (WPScan, GitHub Advisory).
The root cause is a missing server-side validation of the browser-supplied product price on two unauthenticated AJAX actions within the plugin, classified as CWE-862 (Missing Authorization) and categorized under OWASP Top 10 A5: Broken Access Control (WPScan). Because the plugin trusts the price value submitted by the client without verifying it against the actual product price stored server-side, an attacker can craft a request to these unauthenticated endpoints and specify an arbitrary price (e.g., $0.00 or $0.01). This manipulated price is then accepted and reflected in the WooCommerce cart and checkout total when the BOGO offer feature is active. No authentication or special privileges are required to exploit this vulnerability. A proof-of-concept is scheduled for public release on September 25, 2026, to allow time for users to update (WPScan).
Successful exploitation allows unauthenticated attackers to conduct fraudulent transactions by purchasing products at arbitrarily low or zero prices, resulting in direct financial loss for WooCommerce store operators. The integrity of the checkout process is compromised, as manipulated prices carry through to the final order total. There is no direct impact on confidentiality or system availability, but the business impact — including revenue loss and potential for large-scale fraudulent orders — can be significant for affected e-commerce sites (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available, and no evidence of active in-the-wild exploitation has been observed (GitHub Advisory). WPScan has indicated that a PoC will be published on September 25, 2026, following a responsible disclosure window. The vulnerability requires no authentication and is exploitable remotely over the network, lowering the barrier for exploitation once a PoC becomes public. The EPSS score is reported as 0.0 at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).
storegrowth-sales-booster) in a version prior to 2.1.2, using tools like WPScan, Shodan, or manual inspection of plugin directories.price=0.01) in the request body./wp-admin/admin-ajax.php) with price-related parameters set to anomalously low values (e.g., 0, 0.01) from unauthenticated sessions.The vendor has released version 2.1.2 of the StoreGrowth: Smart Sales Booster for WooCommerce plugin, which addresses this vulnerability by adding server-side validation of the product price (WPScan, GitHub Advisory). Site administrators should update the plugin to version 2.1.2 or later immediately. If an immediate update is not possible, a temporary workaround is to disable the BOGO offer feature within the plugin settings, or to restrict access to the affected unauthenticated AJAX actions via a web application firewall (WAF) rule until the patch can be applied.
The vulnerability was discovered and responsibly disclosed by researcher Shikhali Jamalzade (Twitter: @0xAlisAlive), who submitted it through WPScan's vulnerability disclosure program (WPScan). WPScan has verified the vulnerability and is withholding the full proof-of-concept until September 25, 2026, to allow the user community time to apply the patch. No broader media coverage or notable community discussion has been identified at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."