Impact
The WPFunnels WordPress plugin before version 3.13.0 contains an unchecked product ID during the checkout order bump process. An attacker who can submit an order bump request may replace the intended product identifier with that of any available product. The plugin then mistakenly applies the discount configured for the original product to the substituted product, allowing the attacker to purchase it at the reduced price intended for a different item.
Affected Systems
Systems affected are WordPress installations that have the WPFunnels plugin installed at a version earlier than 3.13.0. Any site that enables order bumps or promotional discounts through WPFunnels is vulnerable, and the flaw can only be exploited by unauthenticated users.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is rated medium severity, and an EPSS score of <1% indicates a low likelihood of exploitation at present. Because the flaw allows unauthenticated users to alter the product ID in an order bump, it enables direct monetary loss through discounted purchases. The lack of a KEV listing suggests no widespread exploitation yet, but the potential for financial damage means that this issue warrants immediate attention. An attacker can trigger the vulnerability by crafting a checkout request with an altered product ID, thereby fooling the plugin into applying an off‑target discount.
OpenCVE Enrichment