Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce
CVE-2026-49110

7.5HIGH

What is CVE-2026-49110?

The Upsell Order Bump Offer for WooCommerce plugin versions 3.1.4 and prior exhibit a significant flaw that allows unauthenticated users to exploit broken authentication mechanisms. This vulnerability can lead to unauthorized actions within the WooCommerce environment, enabling an attacker to manipulate pricing and potentially execute fraudulent transactions. It is essential for site administrators to update their plugin versions immediately to mitigate these risks and fortify eCommerce transactions.

Affected Version(s)

Upsell Order Bump Offer for WooCommerce <= 3.1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.