CVE-2026-85350 PUBLISHED

UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together

Assigner: WPScan
Reserved: 03.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.

Product Status

Vendor Unknown
Product UpsellWP
Versions Default: unaffected
  • affected from 1.4.4 to 2.2.10 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE