The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add items to the cart and adjust the quantity to a fractional amount, causing the price to change based on the fractional amount. The vulnerability cannot be exploited if WooCommerce version 9.8.2+ is installed.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress |
|
Vendors & Products |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress |
Mon, 28 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 26 Jul 2025 06:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add items to the cart and adjust the quantity to a fractional amount, causing the price to change based on the fractional amount. The vulnerability cannot be exploited if WooCommerce version 9.8.2+ is installed. | |
Title | MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation | |
Weaknesses | CWE-472 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-07-26T05:45:53.219Z
Updated: 2025-07-28T15:57:21.080Z
Reserved: 2025-07-25T16:26:50.958Z
Link: CVE-2025-8198

Updated: 2025-07-28T15:57:17.792Z

Status : Awaiting Analysis
Published: 2025-07-26T06:15:23.600
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-8198

No data.