Loading market data...
← Back to CVE feed

CVE-2026-79630

MEDIUM CVSS 5.3 View on NVD ↗

Description

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Sep 04, 2026 07:17 UTC Modified: Sep 04, 2026 13:20 UTC