rootpwn

high · CVSS v3 7.5

CVE-2026-85350

The UpsellWP WordPress plugin prior to version 2.2.10 lacks proper input validation when adding products to the cart via Frequently Bought T

Overview

The UpsellWP WordPress plugin prior to version 2.2.10 lacks proper input validation when adding products to the cart via Frequently Bought Together campaigns. This oversight allows unauthenticated remote attackers to purchase arbitrary items at unintended promotional discounts. Consequently, merchants face potential financial loss and unauthorized inventory discounting.

Description

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.

Impact

The vulnerability directly compromises the integrity of financial transactions, falling under the Integrity category of the CIA triad. Unauthenticated malicious actors can exploit this flaw to bypass pricing controls and acquire high-value items at discounted rates. E-commerce merchants running affected versions are impacted through direct revenue loss and potential inventory discrepancies.

Remediation

Update the UpsellWP plugin to version 2.2.10 or later immediately, where proper validation of campaign association for cart additions is implemented. As a temporary mitigation, administrators should disable Frequently Bought Together campaigns if updating is not immediately feasible. Regularly audit e-commerce transaction logs for anomalous pricing or unexpected cart contents.

Risk context

Rated as a high severity vulnerability with a CVSS v3 score of 7.5, representing a significant business logic flaw in e-commerce environments. Organizations utilizing the affected plugin should prioritize patching to prevent financial exploitation. EPSS data is currently unavailable, but immediate remediation is recommended due to the direct impact on revenue.

Affected products

  • UpsellWP UpsellWP plugin < 2.2.10

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.5
CVSS v4
EPSS

WordPress UpsellWP e-commerce price-manipulation insufficient-validation unauthenticated

← All CVEs