Executive brief
A vulnerability exists in a popular WooCommerce extension used to offer additional products to customers during the checkout process. An unauthorized attacker can exploit this flaw to manipulate order details, potentially allowing them to change product prices or bypass standard purchasing rules. This could lead to financial loss for the merchant and unauthorized acquisition of goods.
Technical details
The Upsell Order Bump Offer for WooCommerce plugin (versions 3.1.4 and below) suffers from a broken authentication vulnerability, specifically categorized as improper validation of specified quantity in input (CWE-1284). The flaw allows an unauthenticated remote attacker to perform actions that should be restricted to privileged users or validated system processes. Specifically, the vulnerability enables price manipulation during the checkout process. This occurs because the plugin fails to properly verify the integrity of order data submitted by the user. A fix is available in version 3.1.5.
Affected products
- WP Swings Upsell Order Bump Offer for WooCommerce <= 3.1.4
Timeline
- 2026-05-09: other: Reported by Jakub Herman
- 2026-06-04: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date