Sceawere

Vulnerability Detail

CVE-2026-97275UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Quantity Validation in BuildKit

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
VillaTheme
Product
BuildKit – Product Builder for WooCommerce – Custom PC Builder
Attack Type
Improper Validation of Specified Quantity in Input
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T19:17:26.890Z",
  "pubdate": "2026-10-05T19:17:26.890Z",
  "executiveSummary": "The BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin is susceptible to an Improper Validation of Specified Quantity vulnerability.\nThis flaw allows unauthorized Input Data Manipulation, enabling attackers to modify numerical values associated with product configurations during the building process.\nThe vulnerability affects all versions of the product from n/a through 1.0.28.\nBy manipulating input quantities, an attacker could potentially influence product pricing, inventory logic, or cart totals within the WooCommerce ecosystem.\nThe risk is primarily centered on integrity compromise, where malicious or arbitrary quantity values bypass intended business logic constraints.\nSuccessful exploitation requires the attacker to interact with the plugin's product builder interface, typically requiring no advanced privileges, depending on the site's configuration, but relying on the ability to intercept or modify client-side requests before they reach the server-side validation layer.",
  "technicalDetails": "The vulnerability originates from a failure to adequately sanitize and validate user-supplied quantity inputs within the BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin. Specifically, the component responsible for processing product components and their associated quantities fails to enforce strict bounds or type checking on incoming data before applying it to the underlying WooCommerce cart object or order calculation logic.\nIn the context of the WordPress/WooCommerce request lifecycle, the vulnerability occurs when the plugin processes data submitted via product builder requests. If the plugin fails to implement server-side validation for these specific numeric inputs, the application is susceptible to manipulation. An attacker can use proxy tools or browser developer tools to intercept the request and inject arbitrary integer values—including negative values, zero, or excessively high quantities—into the 'quantity' parameter of the product builder's AJAX or POST requests.\nThe attack flow follows these steps: 1) The attacker initiates a standard session with the product builder. 2) The attacker proceeds to add an item to the builder and intercepts the outgoing request. 3) The attacker modifies the 'quantity' parameter to an unauthorized value. 4) The server processes this payload without secondary validation of the constraints defined in the product builder interface. 5) The manipulated quantity is reflected in the cart session data, which may result in incorrect calculations if the store logic assumes these quantities were validated through the UI.\nBecause WooCommerce relies on the accuracy of quantities for both inventory tracking and financial totals, this input data manipulation can lead to significant discrepancies. By injecting negative quantities, an attacker might potentially reduce the total price of a build to an incorrect value, while large quantities could be used to exhaust server resources or disrupt inventory synchronization. The flaw affects versions 1.0.28 and earlier. No specific authentication is strictly required if the product builder is exposed to guest users, as the lack of server-side validation occurs during the request-handling phase regardless of the user's session state."
}
CVE-2026-97275: Improper Quantity Validation in BuildKit (MEDIUM Severity, CVSS: 5.3) | Sceawere