VYPR

Storegrowth

by WordPress

CVEs (1)

  • CVE-2026-78137Aug 27, 2026
    risk 0.00cvss epss

    The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout…