{"id":105,"date":"2026-04-05T07:26:29","date_gmt":"2026-04-05T07:26:29","guid":{"rendered":"https:\/\/stories.secone4all.com\/?p=105"},"modified":"2026-04-08T06:32:35","modified_gmt":"2026-04-08T06:32:35","slug":"how-i-discovered-critical-price-manipulation","status":"publish","type":"post","link":"https:\/\/stories.secone4all.com\/index.php\/2026\/04\/05\/how-i-discovered-critical-price-manipulation\/","title":{"rendered":"How I discovered critical price manipulation"},"content":{"rendered":"\n<p>Hello Brothers, <\/p>\n\n\n\n<p class=\"has-text-color has-link-color wp-elements-dc6bfdf4d550aa271f2f39e44cc2f890\" style=\"color:#ed22bb\"><strong>I hope you have a nice day. Today I will share how I discovered price manipulation.<\/strong><\/p>\n\n\n\n<p class=\"has-black-color has-vivid-cyan-blue-background-color has-text-color has-background has-link-color wp-elements-68f28e4f6dfab612b05ce1d746564c6e\"><strong>During my holiday, I started testing on a private program. The first thing I did was browse my target and try to discover the site&#8217;s features. After some time of browsing the target, I went to the payment page and started testing the payment functionality.<\/strong><\/p>\n\n\n\n<p class=\"has-black-color has-vivid-green-cyan-background-color has-text-color has-background has-link-color wp-elements-38be0cb3a74b9d764fbbb022b91c3a62\"><strong>There are 3 payment plans, as shown below in the image.<\/strong><br><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"563\" height=\"270\" src=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-39-35.png\" alt=\"\" class=\"wp-image-106\" srcset=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-39-35.png 563w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-39-35-300x144.png 300w\" sizes=\"auto, (max-width: 563px) 100vw, 563px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-text-color has-link-color wp-elements-875b117ead1d0661479bec6d37a6e5a4\" style=\"color:#0000fa\">Annual Plan, Pay upfront. This plan by default offers 20% off.<br><\/li>\n\n\n\n<li class=\"has-text-color has-link-color wp-elements-5e8291101a106ff8c72492db918f443d\" style=\"color:#0000fa\">Annual Plan, Monthly Payment. This plan by default offers 10% off, and the coupon that applied the 10% off exists in the URL.<\/li>\n\n\n\n<li class=\"has-text-color has-link-color wp-elements-5e474801fd17ecf48dd7cbe1224ba054\" style=\"color:#0000fa\">Monthly. This plan does not offer any discount.<\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"has-white-color has-vivid-red-background-color has-text-color has-background has-link-color wp-elements-562852cd274202875283054bcec6ee58\">Now we understand the 3 types of plans, let&#8217;s go to the exploitation.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>First, I switched to the Annual Plan, Monthly Payment plan. I noticed that the coupon_id appears in the URL, as shown below.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"487\" src=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-43-54.png\" alt=\"\" class=\"wp-image-107\" srcset=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-43-54.png 623w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-43-54-300x235.png 300w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/figure>\n\n\n\n<p>After that, I switched back to the Annual Plan, Pay upfront plan and Fill all fields and clicked on next.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"832\" height=\"463\" src=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-48-21.png\" alt=\"\" class=\"wp-image-108\" srcset=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-48-21.png 832w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-48-21-300x167.png 300w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/03\/Screenshot-from-2026-03-26-21-48-21-768x427.png 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><\/figure>\n\n\n\n<p class=\"has-vivid-cyan-blue-background-color has-background\">Then I added the Coupon_id parameter to the URL. I noticed that we can apply 30% off on this plan. By default, this plan allows only 20% off, but using this way I was able to apply 30% off, leading to more significant loss for the company.<\/p>\n\n\n\n<p class=\"has-vivid-cyan-blue-background-color has-background\">Note: When I tried to use the Coupon_id parameter on an unauthorized plan, this didn\u2019t work. But many times I noticed that we can use it on an unauthorized plan if we enter payment details and click on next , then append the Coupon_id to the URL. Otherwise, the PoC doesn\u2019t work.<\/p>\n\n\n\n<p class=\"has-vivid-red-background-color has-background\">This is the response from the customer.<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"473\" height=\"1024\" src=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-473x1024.jpeg\" alt=\"\" class=\"wp-image-111\" srcset=\"https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-473x1024.jpeg 473w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-139x300.jpeg 139w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-768x1662.jpeg 768w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-710x1536.jpeg 710w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436-946x2048.jpeg 946w, https:\/\/stories.secone4all.com\/wp-content\/uploads\/2026\/04\/1767898545436.jpeg 1170w\" sizes=\"auto, (max-width: 473px) 100vw, 473px\" \/><\/figure>\n\n\n\n<p class=\"has-luminous-vivid-amber-background-color has-background\">Unfortunately  This reward is one of many rewards that I was not able to receive, due to my payment profile and my Bugcrowd account being blocked because of unintentionally breaking the payment policy.<\/p>\n\n\n\n<p><strong>Thank you, brothers. I hope this was useful for you.<\/strong> \ud83d\udc4d<\/p>\n\n\n\n<ul class=\"wp-block-social-links is-layout-flex wp-block-social-links-is-layout-flex\"><li class=\"wp-social-link wp-social-link-linkedin  wp-block-social-link\"><a href=\"https:\/\/www.linkedin.com\/in\/muhammad-mubarak-941b85290?utm_source=share&#038;utm_campaign=share_via&#038;utm_content=profile&#038;utm_medium=ios_app\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M19.7,3H4.3C3.582,3,3,3.582,3,4.3v15.4C3,20.418,3.582,21,4.3,21h15.4c0.718,0,1.3-0.582,1.3-1.3V4.3 C21,3.582,20.418,3,19.7,3z M8.339,18.338H5.667v-8.59h2.672V18.338z M7.004,8.574c-0.857,0-1.549-0.694-1.549-1.548 c0-0.855,0.691-1.548,1.549-1.548c0.854,0,1.547,0.694,1.547,1.548C8.551,7.881,7.858,8.574,7.004,8.574z M18.339,18.338h-2.669 v-4.177c0-0.996-0.017-2.278-1.387-2.278c-1.389,0-1.601,1.086-1.601,2.206v4.249h-2.667v-8.59h2.559v1.174h0.037 c0.356-0.675,1.227-1.387,2.526-1.387c2.703,0,3.203,1.779,3.203,4.092V18.338z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">LinkedIn<\/span><\/a><\/li>\n\n<li class=\"wp-social-link wp-social-link-medium  wp-block-social-link\"><a href=\"https:\/\/medium.com\/@mohammed01550038865\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M13.2,12c0,3-2.4,5.4-5.3,5.4S2.6,15,2.6,12s2.4-5.4,5.3-5.4S13.2,9,13.2,12 M19.1,12c0,2.8-1.2,5-2.7,5s-2.7-2.3-2.7-5s1.2-5,2.7-5C17.9,7,19.1,9.2,19.1,12 M21.4,12c0,2.5-0.4,4.5-0.9,4.5c-0.5,0-0.9-2-0.9-4.5s0.4-4.5,0.9-4.5C21,7.5,21.4,9.5,21.4,12\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">Medium<\/span><\/a><\/li>\n\n<li class=\"wp-social-link wp-social-link-x  wp-block-social-link\"><a href=\"https:\/\/x.com\/mohamme31752968?s=21\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M13.982 10.622 20.54 3h-1.554l-5.693 6.618L8.745 3H3.5l6.876 10.007L3.5 21h1.554l6.012-6.989L15.868 21h5.245l-7.131-10.378Zm-2.128 2.474-.697-.997-5.543-7.93H8l4.474 6.4.697.996 5.815 8.318h-2.387l-4.745-6.787Z\" \/><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">X<\/span><\/a><\/li><\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello Brothers, I hope you have a nice day. Today I will share how I discovered price manipulation. During my holiday, I started testing on a private program. The first thing I did was browse my target and try to discover the site&#8217;s features. After some time of browsing the target, I went to the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":111,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,7,4,6],"tags":[],"class_list":["post-105","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bug-bounty","category-bugcrowd","category-ethical-hacking","category-hackerone"],"acf":[],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/posts\/105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/comments?post=105"}],"version-history":[{"count":7,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/posts\/105\/revisions"}],"predecessor-version":[{"id":118,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/posts\/105\/revisions\/118"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/media\/111"}],"wp:attachment":[{"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/media?parent=105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/categories?post=105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stories.secone4all.com\/index.php\/wp-json\/wp\/v2\/tags?post=105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}