CVE-2026-85350
UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
| Vendor | unknown |
| Product | upsellwp |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown upsellwp
Be the first to know when new unknown vulnerabilities affecting unknown upsellwp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / UpsellWP
1.4.4 < 2.2.10
References
Credits
Pedro Pinho WPScan