PT-2025-17887 · WordPress · Upsell Funnel Builder For Woocommerce

Pwn4Thelulz

·

Publicado

2025-04-25

·

Atualizado

2025-04-25

·

CVE-2025-3743

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Upsell Funnel Builder for WooCommerce plugin for WordPress versions up to, and including, 3.0.0
Description The issue allows unauthenticated attackers to manipulate orders by updating the product associated with any order bump and the discount applied to any order bump item when adding it to the cart. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the add offer in cart function.
Recommendations For versions up to, and including, 3.0.0, update to a version higher than 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the add offer in cart function to prevent unauthenticated attackers from manipulating orders.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-3743

Produtos afetados

Upsell Funnel Builder For Woocommerce