Insecure Direct Object Reference Vulnerability in Simple Shopping Cart Plugin for WordPress
CVE-2025-3889
What is CVE-2025-3889?
The Simple Shopping Cart plugin for WordPress is vulnerable to an Insecure Direct Object Reference due to inadequate data validation in the 'process_payment_data' function. This flaw allows unauthenticated attackers to exploit the application by altering the product quantity to a negative value, effectively reducing the total order cost. This attack is only viable when using the Manual Checkout mode since other payment processors like PayPal and Stripe will reject any payments processed for a negative quantity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress Simple Shopping Cart * <= 5.1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved