CVE-2025-3743 | Upsell Funnel Builder for WooCommerce Plugin up to 3.0.0 on WordPress add_offer_in_cart ID/discount external control of assumed-immutable web parameter
A vulnerability was found in Upsell Funnel Builder for WooCommerce Plugin up to 3.0.0 on WordPress and classified as critical. Affected by this issue is the function add_offer_in_cart. The manipulation of the argument ID/discount leads to external control of assumed-immutable web parameter.
This vulnerability is handled as CVE-2025-3743. The attack may be launched remotely. There is no exploit available.