Executive brief
The Upsell Order Bump Offer for WooCommerce is a WordPress plugin that enables online merchants to offer additional products during checkout. An unauthenticated attacker can inject malicious scripts through the plugin's interface that execute in visitors' browsers, potentially stealing customer data, hijacking accounts, or redirecting users to phishing pages. This directly threatens customer trust and the security of e-commerce transactions.
Technical details
This is a reflected or stored Cross-Site Scripting (XSS) vulnerability (CWE-79) in the Upsell Order Bump Offer for WooCommerce plugin versions 3.1.5 and earlier. The vulnerability requires user interaction—an attacker must trick an admin or privileged user into clicking a malicious link or visiting a crafted page to trigger the XSS payload. No authentication is required for the attack vector itself, though exploitation may depend on the victim's privilege level. Successful exploitation allows arbitrary JavaScript execution in the context of the affected user's browser session, enabling account takeover, data theft, or further malicious actions. The vulnerability has been patched in version 3.1.6.
Affected products
- Upsell Order Bump Offer for WooCommerce Upsell Order Bump Offer for WooCommerce 3.1.5 and earlier
Timeline
- 2026-09-02: disclosed: Published on NVD
- 2026-09: patched: Fixed in version 3.1.6
- 2026-08-02: other: Reported by Ivaylo Atanassov