CVE-2025-3889 | Simple Shopping Cart Plugin up to 5.1.3 on WordPress process_payment_data quantity resource injection
A vulnerability, which was classified as critical, was found in Simple Shopping Cart Plugin up to 5.1.3 on WordPress. This affects the function process_payment_data. The manipulation of the argument quantity leads to improper control of resource identifiers.
This vulnerability is uniquely identified as CVE-2025-3889. It is possible to initiate the attack remotely. There is no exploit available.