Junglewise Threat Intelligence

CVE-2026-85350: UpsellWP Frequently Bought Together price manipulation

CVE-2026-85350 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Executive brief

UpsellWP is a WordPress plugin that helps online stores run promotional campaigns to encourage customers to buy multiple items together at discounted prices. A flaw in the plugin fails to verify that products added to the cart during a "Frequently Bought Together" campaign actually belong to that campaign, allowing anyone to purchase any product at unintended discount prices, potentially causing significant revenue loss.

Technical details

The vulnerability is an authentication/authorization bypass in the UpsellWP plugin's cart handling logic for Frequently Bought Together campaigns. The plugin does not validate that products added to the cart via campaign requests actually belong to the active campaign, permitting unauthenticated users to bypass discount eligibility checks and purchase arbitrary products at campaign discounted prices. No authentication is required; the attack is performed through direct manipulation of cart parameters during the shopping process. An attacker can selectively apply campaign discounts to any product, resulting in revenue loss and potential business impact. The vulnerability was patched in version 2.2.10.

Affected products

  • UpsellWP UpsellWP before 2.2.10

Timeline

  • 2026-09-16: disclosed
  • 2026-09-18: patched: Version 2.2.10 released

References