← Back to CVE List
CVE-2026-85350NVD
Description
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| Unknown UpsellWP | 1.4.4 - < 2.2.10 | N/A |