high · CVSS v3 7.5
CVE-2026-85350
The UpsellWP WordPress plugin prior to version 2.2.10 lacks proper input validation when adding products to the cart via Frequently Bought T
Overview
The UpsellWP WordPress plugin prior to version 2.2.10 lacks proper input validation when adding products to the cart via Frequently Bought Together campaigns. This oversight allows unauthenticated remote attackers to purchase arbitrary items at unintended promotional discounts. Consequently, merchants face potential financial loss and unauthorized inventory discounting.
Description
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
Impact
The vulnerability directly compromises the integrity of financial transactions, falling under the Integrity category of the CIA triad. Unauthenticated malicious actors can exploit this flaw to bypass pricing controls and acquire high-value items at discounted rates. E-commerce merchants running affected versions are impacted through direct revenue loss and potential inventory discrepancies.
Remediation
Update the UpsellWP plugin to version 2.2.10 or later immediately, where proper validation of campaign association for cart additions is implemented. As a temporary mitigation, administrators should disable Frequently Bought Together campaigns if updating is not immediately feasible. Regularly audit e-commerce transaction logs for anomalous pricing or unexpected cart contents.
Risk context
Rated as a high severity vulnerability with a CVSS v3 score of 7.5, representing a significant business logic flaw in e-commerce environments. Organizations utilizing the affected plugin should prioritize patching to prevent financial exploitation. EPSS data is currently unavailable, but immediate remediation is recommended due to the direct impact on revenue.
Affected products
- UpsellWP UpsellWP plugin < 2.2.10
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —