PT-2025-17887 · WordPress · Upsell Funnel Builder For Woocommerce

Pwn4Thelulz

·

Published

2025-04-25

·

Updated

2025-04-25

·

CVE-2025-3743

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Upsell Funnel Builder for WooCommerce plugin for WordPress versions up to, and including, 3.0.0
Description The issue allows unauthenticated attackers to manipulate orders by updating the product associated with any order bump and the discount applied to any order bump item when adding it to the cart. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the add offer in cart function.
Recommendations For versions up to, and including, 3.0.0, update to a version higher than 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the add offer in cart function to prevent unauthenticated attackers from manipulating orders.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-3743

Affected Products

Upsell Funnel Builder For Woocommerce