
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78137 is an unauthenticated arbitrary price manipulation vulnerability in the StoreGrowth: Smart Sales Booster for WooCommerce WordPress plugin. The flaw allows unauthenticated attackers to add products to the shopping cart at an attacker-chosen price, which carries through to the checkout total when the BOGO (Buy One Get One) offer feature is enabled. It affects all versions of the plugin before 2.1.2 and was publicly disclosed on August 25, 2026, with the CVE published on August 27, 2026. The vulnerability carries a CVSS score of 7.5 (High) and was discovered and reported by researcher Shikhali Jamalzade (WPScan, GitHub Advisory).
The root cause is a missing server-side validation of the browser-supplied product price on two unauthenticated AJAX actions within the plugin, classified as CWE-862 (Missing Authorization) and categorized under OWASP Top 10 A5: Broken Access Control (WPScan). Because the plugin trusts the price value submitted by the client without verifying it against the actual product price stored server-side, an attacker can craft a request to these unauthenticated endpoints and specify an arbitrary price (e.g., $0.00 or $0.01). This manipulated price is then accepted and reflected in the WooCommerce cart and checkout total when the BOGO offer feature is active. No authentication or special privileges are required to exploit this vulnerability. A proof-of-concept is scheduled for public release on September 25, 2026, to allow time for users to update (WPScan).
Successful exploitation allows unauthenticated attackers to conduct fraudulent transactions by purchasing products at arbitrarily low or zero prices, resulting in direct financial loss for WooCommerce store operators. The integrity of the checkout process is compromised, as manipulated prices carry through to the final order total. There is no direct impact on confidentiality or system availability, but the business impact — including revenue loss and potential for large-scale fraudulent orders — can be significant for affected e-commerce sites (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available, and no evidence of active in-the-wild exploitation has been observed (GitHub Advisory). WPScan has indicated that a PoC will be published on September 25, 2026, following a responsible disclosure window. The vulnerability requires no authentication and is exploitable remotely over the network, lowering the barrier for exploitation once a PoC becomes public. The EPSS score is reported as 0.0 at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).
storegrowth-sales-booster) in a version prior to 2.1.2, using tools like WPScan, Shodan, or manual inspection of plugin directories.price=0.01) in the request body./wp-admin/admin-ajax.php) with price-related parameters set to anomalously low values (e.g., 0, 0.01) from unauthenticated sessions.The vendor has released version 2.1.2 of the StoreGrowth: Smart Sales Booster for WooCommerce plugin, which addresses this vulnerability by adding server-side validation of the product price (WPScan, GitHub Advisory). Site administrators should update the plugin to version 2.1.2 or later immediately. If an immediate update is not possible, a temporary workaround is to disable the BOGO offer feature within the plugin settings, or to restrict access to the affected unauthenticated AJAX actions via a web application firewall (WAF) rule until the patch can be applied.
The vulnerability was discovered and responsibly disclosed by researcher Shikhali Jamalzade (Twitter: @0xAlisAlive), who submitted it through WPScan's vulnerability disclosure program (WPScan). WPScan has verified the vulnerability and is withholding the full proof-of-concept until September 25, 2026, to allow the user community time to apply the patch. No broader media coverage or notable community discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."