Impact
The WPFunnels WordPress plugin before version 3.13.0 contains an unchecked product ID during the checkout order bump process. An attacker that can submit an order bump request can replace the intended product identifier with that of any available product. The plugin then mistakenly applies the discount configured for the original product to the substituted product, allowing the attacker to purchase the latter at a reduced price intended for another. This flaw results in unauthenticated price manipulation, potentially enabling the attacker to acquire paid products for less than their market value.
Affected Systems
Systems affected are WordPress installations that have the WPFunnels plugin installed at a version earlier than 3.13.0. Any site that enables order bumps or promotional discounts through WPFunnels is vulnerable. The issue applies regardless of the user’s role; authenticated or unauthenticated users can exploit it.
Risk and Exploitability
The flaw carries no known exploit code and the EPSS score is not available, but the characteristics of the vulnerability—no authentication required, direct manipulation of order parameters, and a monetary impact—make it a high‑impact type. The absence of a KEV listing suggests no large‑scale exploitation yet, yet the potential for significant financial loss warrants immediate attention. An attacker can trigger the vulnerability by crafting a checkout request with an altered product ID, thereby fooling the plugin into applying an off‑target discount.
OpenCVE Enrichment