Unauthenticated XSS Vulnerability in Upsell Order Bump Offer for WooCommerce
CVE-2026-81288

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81288?

An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the Upsell Order Bump Offer plugin for WooCommerce, allowing attackers to execute malicious scripts on user browsers by tricking them into loading a crafted page. This issue affects all versions up to 3.1.5 and highlights the importance of securing WordPress plugins to prevent exploitations that could compromise user data and site integrity.

Affected Version(s)

Upsell Order Bump Offer for WooCommerce <= 3.1.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivaylo Atanassov | Patchstack Bug Bounty Program
.