PT-2025-30965 · WordPress · Woodmart

·

CVE-2025-8097

·

Published

2025-07-26

·

Updated

2025-07-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WoodMart versions prior to 8.2.7
Description The WoodMart theme for WordPress is susceptible to improper input validation. Insufficient validation of the qty parameter within the woodmart update cart item function allows unauthenticated attackers to manipulate cart quantities using fractional values. This manipulation can result in cart totals rounding to $0.00, effectively bypassing payment requirements and enabling unauthorized acquisition of virtual or downloadable products.
Recommendations Update WoodMart to version 8.2.7 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8097

Affected Products

Woodmart