5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter in the woodmart_update_cart_item function. This makes it possible for unauthenticated attackers to manipulate cart quantities using fractional values, allowing them to obtain products for free by setting extremely small quantities (e.g., 0.00001) that round cart totals to $0.00, effectively bypassing payment requirements and allowing unauthorized acquisition of virtual or downloadable products.
Basic Information
ID
CVE-2025-8097
Source
Wordfence
Published
Jul 26, 2025 at 06:43
Modified
Jul 28, 2025 at 15:51
Affected Product
Vendor
xTemos
Product
Woodmart
Version
*
Affected Versions
xTemos Woodmart *