CVE-2026-79630
Received Received - Intake

WPFunnels Discount Bypass via Order Bump Misconfiguration

Vulnerability report for CVE-2026-79630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: WPScan

Description

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpfunnels wpfunnels to 3.13.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WPFunnels WordPress plugin before version 3.13.0. It allows unauthenticated users to manipulate product prices during checkout by changing the product ID in an order bump. The plugin does not verify if the requested product matches the one configured for the discount, enabling users to purchase any product at a lower price intended for another product. This reduced price is then applied to the total order.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the WPFunnels plugin version prior to 3.13.0. You can do this by inspecting the plugin files or using WordPress admin panel to view the installed version. No specific commands are provided in the context, but monitoring checkout processes for unexpected price changes or product substitutions may indicate exploitation.

Impact Analysis

Unauthenticated attackers could exploit this to purchase products at unauthorized discounted prices, leading to financial losses for the store owner. Customers might also unknowingly benefit from unintended discounts, causing pricing inconsistencies and potential disputes. The vulnerability could also damage the store's reputation and trust.

Compliance Impact

This vulnerability could potentially violate compliance with financial and data protection regulations such as GDPR or HIPAA by enabling unauthorized discounts on products, which may lead to improper financial transactions or data handling. Unauthenticated price manipulation could result in financial losses for vendors and undermine trust in transaction integrity.

Mitigation Strategies

Immediately update the WPFunnels plugin to version 3.13.0 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review recent orders for any unauthorized discounts or product substitutions as a precaution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart