CVE-2026-81288
largeUnauthenticated XSS in Upsell Order Bump Offer for WooCommerce (<= 3.1.5)
CVE-2026-81288 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the Upsell Order Bump Offer for WooCommerce WordPress plugin, affecting all versions up to and including 3.1.5. Because no authentication is required, an unauthenticated attacker can inject malicious script that executes when a victim — per the CVSS user-interaction requirement, most plausibly a store admin or shopper — views a crafted link, request, or page; the CVSS scope-change flag indicates the injected script can act beyond the vulnerable component's normal trust boundary. A successful attack lets the attacker run arbitrary JavaScript in the victim's browser on the WooCommerce store, enabling actions such as stealing session cookies or performing unintended actions in the victim's context. Any WordPress/WooCommerce site running the plugin at version 3.1.5 or older is affected. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Update the plugin to the latest release (any version after 3.1.5; confirm the exact fixed version in the vendor changelog). Until patched, administrators should review recently changed or added admin accounts and check checkout/upsell pages for unexpected scripts or injected content, since an unauthenticated XSS can target admin browsers. Monitor the plugin page for the patched release and consider web-application-filter rules on plugin endpoints.
| WP Swings Upsell Order Bump Offer for WooCommerce (WordPress/WooCommerce plugin) | <= 3.1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.