SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81288

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Upsell Order Bump Offer for WooCommerce versions up to 3.1.5 are vulnerable to unauthenticated Cross Site Scripting (XSS), allowing attackers to inject malicious scripts that could compromise user data or session integrity. This high-severity vulnerability should be prioritized by WooCommerce site administrators and developers to mitigate potential exploitation risks. Immediate updates or patches are recommended to safeguard against this threat.

CVE
CVE-2026-81288
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.