MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation

CVE Details

Basic Information

Title MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation
Type cve
Published 2025-07-26T05:45:53.219Z
Modified 2025-07-26T05:45:53.219Z

Product Information

Vendor ThemeMove
Product MinimogWP – The High Converting eCommerce WordPress Theme
Version *

CVSS Information

Base Score 7.5 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Analysis

AI Description The MinimogWP theme for WordPress allows unauthenticated attackers to manipulate prices by exploiting insufficient quantity checks in the cart. This affects versions up to 3.9.0. However, the vulnerability is mitigated if WooCommerce 9.8.2+ is installed.
AI Severity High
AI Vendor WordPress Community
AI Product MinimogWP
AI Version 3.9.0

Affected Products

  • ThemeMove MinimogWP – The High Converting eCommerce WordPress Theme *

Additional Information

CWE List CWE-472
Source Wordfence

Description

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add items to the cart and adjust the quantity to a fractional amount, causing the price to change based on the fractional amount. The vulnerability cannot be exploited if WooCommerce version 9.8.2+ is installed.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.