CVE-2026-85350: UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together
Published Sep 18, 2026
·Updated
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
Affected Software
1 affected component
WordPress plugin UpsellWP<2.2.10
Event History
Sep 18, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit it; no account or authenticated access is required.
2
What does an attacker need to do to obtain an improper discount?
The attacker needs to add arbitrary products to the cart through a Frequently Bought Together campaign. The plugin does not verify that those products actually belong to that campaign.
3
Which installations are affected?
UpsellWP versions before 2.2.10 are affected. Exposure depends on use of a Frequently Bought Together campaign with a discounted price.