Wordpress Alert: Cart total manipulation
An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.
What it looks like
An extension trusts a client-submitted total instead of recalculating server-side.
Why it matters
A buyer may be charged less than the actual order value.
What to check
Review custom cart logic and reconcile final totals on the server.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce REST API overview, WooCommerce security FAQ.
- Categories: WordPress
- Tags: #WordPress Security, #WooCommerce