Insecure Direct Object Reference Vulnerability in Simple Shopping Cart Plugin for WordPress
CVE-2025-3889
5.3MEDIUM
What is CVE-2025-3889?
The Simple Shopping Cart plugin for WordPress is vulnerable to an Insecure Direct Object Reference due to inadequate data validation in the 'process_payment_data' function. This flaw allows unauthenticated attackers to exploit the application by altering the product quantity to a negative value, effectively reducing the total order cost. This attack is only viable when using the Manual Checkout mode since other payment processors like PayPal and Stripe will reject any payments processed for a negative quantity.
Affected Version(s)
WordPress Simple Shopping Cart * <= 5.1.3