CVE-2026-85350
Last modified
CVE-2026-85350 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price..
Description
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | UpsellWP | >= 1.4.4, < 2.2.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-85350?
How severe is CVE-2026-85350?
How do I fix CVE-2026-85350?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85311Missing Authorization vulnerability in Kings Plugins MarketK…5.3
- CVE-2026-8532Integer overflow in XML in Google Chrome prior to 148.0.7778…8.8
- CVE-2026-8533Use after free in Accessibility in Google Chrome prior to 14…8.3
- CVE-2026-8534Integer overflow in GPU in Google Chrome on Linux and Chrome…8.3
- CVE-2026-85349The FluentBoards WordPress plugin before 2.0.15 does not pr…4.3
- CVE-2026-8535Out of bounds read in Media in Google Chrome on Linux and Ch…5.3
- CVE-2026-8536Insufficient validation of untrusted input in ReadingMode in…3.1
- CVE-2026-85360Use after free in Windows Kernel allows an authorized attack…7
- CVE-2026-8537Insufficient policy enforcement in ViewTransitions in Google…4.3
- CVE-2026-85378A vulnerability was identified in light0011 cms c774dce31c6d…7.3
- CVE-2026-85379A security flaw has been discovered in light0011 cms c774dce…7.3
- CVE-2026-8538Insufficient validation of untrusted input in GPU in Google …5.3
Are you affected by CVE-2026-85350?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
