๐Ÿ” CVE Alert

CVE-2026-85350

UNKNOWN 0.0

UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.

Vendor unknown
Product upsellwp
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown upsellwp

Be the first to know when new unknown vulnerabilities affecting unknown upsellwp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / UpsellWP
1.4.4 < 2.2.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5068ff54-8632-42bd-b50a-4ecb6ac5853f/

Credits

Pedro Pinho WPScan