Description
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
Published: 2026-09-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross‑site scripting flaw exists in the Upsell Order Bump Offer for WooCommerce plugin for versions up to and including 3.1.5. The flaw allows an attacker to inject arbitrary scripts into the plugin’s configuration pages, which may be executed in the browsers of site visitors or administrators. This can result in cookie theft, session hijacking, defacement, or the delivery of additional malicious payloads.

Affected Systems

The weakness affects the WP Swings Upsell Order Bump Offer for WooCommerce plugin, version 3.1.5 and older, used within WordPress sites that offer WooCommerce checkout upsells.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score is currently unavailable, suggesting the exploit may not yet be widely observed. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit is unauthenticated, any user who can load the affected configuration page—either a visitor or an administrator—could trigger the injection. Successful exploitation would allow the attacker to run scripts within the context of the site, compromising confidentiality, integrity, or availability of the site’s data and users.

Generated by OpenCVE AI on September 2, 2026 at 12:27 UTC.

Remediation

Vendor Solution

Update the WordPress Upsell Order Bump Offer for WooCommerce Plugin to the latest available version (at least 3.1.6).


OpenCVE Recommended Actions

  • Update the Upsell Order Bump Offer for WooCommerce Plugin to version 3.1.6 or newer immediately
  • Restrict access to the order bump configuration UI to administrative users only, reducing the attack surface
  • If an immediate update is not possible, disable the order bump feature or remove the plugin until the update is applied

Generated by OpenCVE AI on September 2, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Swings
Wp Swings upsell Order Bump Offer For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wp Swings
Wp Swings upsell Order Bump Offer For Woocommerce

Wed, 02 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
Title WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wp Swings Upsell Order Bump Offer For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T16:00:43.097Z

Reserved: 2026-08-26T17:33:24.197Z

Link: CVE-2026-81288

cve-icon Vulnrichment

Updated: 2026-09-02T13:42:32.650Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:12.530

Modified: 2026-09-02T16:17:25.820

Link: CVE-2026-81288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T12:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')