CVE-2025-3743
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 472
Summary
CVE-2025-3743: The Upsell Funnel Builder plugin for WooCommerce in WordPress, affecting versions up to 3.0.0, has a vulnerability that enables unauthenticated attackers to manipulate orders. Specifically, the 'add_offer_in_cart' function allows unauthorized modification of the product ID and discount fields related to order bumps. As a result, attackers can arbitrarily update the product associated with any order bump and the discount applied to it, posing a significant risk to e-commerce sites using this plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.