CVE-2026-81288: WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Upsell Order Bump Offer for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 3.1.6
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation still requires user interaction, as reflected by the UI:R vector.
What security impact can successful exploitation have?
The supplied CVSS vector indicates low-impact confidentiality, integrity, and availability effects, with scope changed. The vulnerability is classified as cross-site scripting (XSS), meaning malicious script execution in a victim's browser is the relevant attack type.
Which plugin versions are affected?
Versions 3.1.5 and earlier of Upsell Order Bump Offer for WooCommerce are identified as affected. The provided data does not state a fixed version.