Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-472'

View all threats tagged with 'cwe-472'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-472

Threats Tagged 'cwe-472'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-67363: CWE-472: External Control of Assumed-Immutable Web Parameter in balbooa.com Balbooa Forms extension for JoomlaCVE-2026-67363
0

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.

Join the discussion
CVE-2026-15045: CWE-472 External Control of Assumed-Immutable Web Parameter in Wallet System for WooCommerceCVE-2026-15045
0

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.

Join the discussion
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native… (CVE-2026-16067)CVE-2026-16067
0

The Event Booking Manager for WooCommerce (Pro) WordPress plugin versions before 5.0.3 contains a vulnerability where the ticket price is not validated on the server during its native checkout process. This flaw allows unauthenticated users to supply arbitrary ticket prices, potentially booking paid event tickets for free and obtaining valid bookings without payment.

Join the discussion
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in… (CVE-2026-16620)CVE-2026-16620
0

The WPC Name Your Price for WooCommerce WordPress plugin versions before 2.2.5 contain a vulnerability where the server-side price allowlist is not enforced for products configured in "Select" price mode. This allows unauthenticated visitors to add products to the cart at arbitrary prices below the allowed values and place orders at those underpriced amounts, potentially causing revenue loss. This issue is distinct from a previous vulnerability fixed in version 2.2.0 and remains unpatched through 2.2.4.

Join the discussion
CVE-2026-15149: CWE-20 Improper Input Validation in WP Hotel BookingCVE-2026-15149
0

CVE-2026-15149 is a medium severity vulnerability in the WP Hotel Booking WordPress plugin before version 2.3.3. The plugin does not properly validate that room quantities and order totals are non-negative during booking. It relies on client-controlled cart data, which allows unauthenticated users to create confirmed reservations for free or at a reduced price.

Join the discussion
CVE-2026-10524: CWE-472 External Control of Assumed-Immutable Web Parameter in CoCartCVE-2026-10524
0

CVE-2026-10524 is a vulnerability in the CoCart WordPress plugin before version 4.9.0. It allows unauthenticated users to manipulate product prices by supplying arbitrary price values through a public REST API endpoint. This flaw enables attackers to complete WooCommerce orders at manipulated totals without validation against actual product prices.

Join the discussion
CVE-2026-1982: CWE-472 External Control of Assumed-Immutable Web ParameterCVE-2026-1982
0

The Persian Elementor plugin for WordPress up to version 2.8.1 contains a vulnerability that allows unauthenticated attackers to manipulate payment amounts submitted to the ZarinPal payment gateway. This occurs because the plugin does not perform server-side validation of the 'amount' parameter, trusting user-supplied values instead. This can lead to attackers submitting arbitrary payment amounts, potentially bypassing intended pricing controls.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cwe-472
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses