CVE-2026-78137

CVE-2026-78137: StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart

Vendor Unknown
Product StoreGrowth
Published August 27, 2026
Last update August 27, 2026

CVSS base score

What the vulnerability does

01Description

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated