CVE-2026-85350
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
- Published Sep 18, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available