Impact
An unauthenticated cross‑site scripting flaw exists in the Upsell Order Bump Offer for WooCommerce plugin for versions up to and including 3.1.5. The flaw allows an attacker to inject arbitrary scripts into the plugin’s configuration pages, which may be executed in the browsers of site visitors or administrators. This can result in cookie theft, session hijacking, defacement, or the delivery of additional malicious payloads.
Affected Systems
The weakness affects the WP Swings Upsell Order Bump Offer for WooCommerce plugin, version 3.1.5 and older, used within WordPress sites that offer WooCommerce checkout upsells.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score is currently unavailable, suggesting the exploit may not yet be widely observed. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit is unauthenticated, any user who can load the affected configuration page—either a visitor or an administrator—could trigger the injection. Successful exploitation would allow the attacker to run scripts within the context of the site, compromising confidentiality, integrity, or availability of the site’s data and users.
OpenCVE Enrichment