VYPR
Unrated severityNVD Advisory· Published Aug 29, 2019· Updated Aug 5, 2024

CVE-2019-14978

CVE-2019-14978

Description

Parameter tampering in WooCommerce PayU India Payment Gateway plugin 2.1.1 allows price manipulation via the purchaseQuantity parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Parameter tampering in WooCommerce PayU India Payment Gateway plugin 2.1.1 allows price manipulation via the purchaseQuantity parameter.

Vulnerability

The WooCommerce PayU India Payment Gateway plugin version 2.1.1 for WordPress contains a parameter tampering vulnerability in the /payu/icpcheckout/ endpoint. The purchaseQuantity=1 parameter is not properly validated, allowing an attacker to modify the quantity value to manipulate the total price during checkout.

Exploitation

An attacker can exploit this by intercepting the checkout request and altering the purchaseQuantity parameter to a lower value, thereby reducing the total cost of the item. No authentication is required beyond being able to initiate a checkout session.

Impact

Successful exploitation allows an attacker to purchase items for a lower price than intended, resulting in financial loss for the merchant. The integrity of the transaction is compromised.

Mitigation

The vendor has not released a patched version as of the publication date (2019-08-29). Users should consider disabling the plugin or implementing additional server-side validation of the purchase quantity parameter until a fix is available.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.