SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 2.7.0 - Unauthenticated Price Manipulation via 'sellkit_product_prices' Parameter

High 7.5 CWE-472Fixed in 2.8.0
ID
WPSEC-2026-0485
Plugin
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster (sellkit)
Affected
from 2.3.5 before 2.8.0
Remediation
Update to 2.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-472
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster on WPSec AttackSurface
Fix released
Published

Description

The SellKit plugin for WordPress is vulnerable to Price Manipulation via the 'sellkit_product_prices' parameter in versions 2.3.5 up to, and including, 2.7.0. This is due to the cart price calculation hook (in both the Elementor and block editor checkout implementations) trusting a client-supplied JSON map of product IDs to prices, intended to carry upsell prices back from a hidden checkout form field, and applying those values to matching cart items with set_price() when the order is placed. This makes it possible for unauthenticated attackers to purchase products at arbitrary prices, including zero, by adding the parameter to a checkout submission.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0