Checkout Order Bump Exploit in WPFunnels WordPress Plugin
CVE-2026-79630
Key Information:
Badges
What is CVE-2026-79630?
The WPFunnels plugin for WordPress, prior to version 3.13.0, contains a security issue where it fails to properly verify that the product selected through a checkout order bump corresponds to the product intended for the discount. As a result, this flaw allows unauthenticated users to exploit the order bump feature, gaining unauthorized discounts on any purchasable product. This vulnerability can lead to financial losses for merchants due to incorrect pricing calculations on their transactions.
Affected Version(s)
WPFunnels 0 < 3.13.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved