Junglewise Threat Intelligence

CVE-2026-81288: Upsell Order Bump Offer for WooCommerce unauthenticated cross-site scripting

CVE-2026-81288 · Severity: high · CVSS 7.1 · Published 2026-09-02

Executive brief

The Upsell Order Bump Offer for WooCommerce is a WordPress plugin that enables online merchants to offer additional products during checkout. An unauthenticated attacker can inject malicious scripts through the plugin's interface that execute in visitors' browsers, potentially stealing customer data, hijacking accounts, or redirecting users to phishing pages. This directly threatens customer trust and the security of e-commerce transactions.

Technical details

This is a reflected or stored Cross-Site Scripting (XSS) vulnerability (CWE-79) in the Upsell Order Bump Offer for WooCommerce plugin versions 3.1.5 and earlier. The vulnerability requires user interaction—an attacker must trick an admin or privileged user into clicking a malicious link or visiting a crafted page to trigger the XSS payload. No authentication is required for the attack vector itself, though exploitation may depend on the victim's privilege level. Successful exploitation allows arbitrary JavaScript execution in the context of the affected user's browser session, enabling account takeover, data theft, or further malicious actions. The vulnerability has been patched in version 3.1.6.

Affected products

  • Upsell Order Bump Offer for WooCommerce Upsell Order Bump Offer for WooCommerce 3.1.5 and earlier

Timeline

  • 2026-09-02: disclosed: Published on NVD
  • 2026-09: patched: Fixed in version 3.1.6
  • 2026-08-02: other: Reported by Ivaylo Atanassov

References