Unrated severityNVD Advisory· Published Aug 27, 2026
CVE-2026-78137
CVE-2026-78137
Description
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<2.1.2+ 1 more
- (no CPE)range: <2.1.2
- (no CPE)range: <2.1.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.