Impact
The UpsellWP WordPress plugin versions earlier than 2.2.10 fails to verify that items added to the cart through a Frequently Bought Together campaign are actually part of that campaign. As a result, any user without authentication can purchase arbitrary products at the discounted campaign price, potentially leading to unauthorized revenue loss and fraud. This flaw is a vulnerability in authentication logic, identified as CWE-287.
Affected Systems
WordPress sites that have the UpsellWP plugin installed in any configuration before version 2.2.10 are vulnerable. No specific vendor or product name beyond the plugin itself is provided, and affected versions span all releases prior to 2.2.10.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score of <1% suggests that, at present, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending unauthenticated requests to add non‑campaign items to the cart; the impact is limited to financial loss per transaction but could scale with repeated use.
OpenCVE Enrichment