PT-2025-30965 · WordPress · Woodmart

Samir El Khaouti

·

Published

2025-07-26

·

Updated

2025-07-26

·

CVE-2025-8097

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WoodMart versions prior to 8.2.7
Description The WoodMart theme for WordPress is susceptible to improper input validation. Insufficient validation of the qty parameter within the woodmart update cart item function allows unauthenticated attackers to manipulate cart quantities using fractional values. This manipulation can result in cart totals rounding to $0.00, effectively bypassing payment requirements and enabling unauthorized acquisition of virtual or downloadable products.
Recommendations Update WoodMart to version 8.2.7 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-8097

Affected Products

Woodmart