What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Blind SQL Injection.This issue affects UpsellWP: from n/a through <= 2.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
UpsellWP versions 2.2.4 and earlier contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or equivalent access can inject malicious SQL code through unfiltered input, potentially reading sensitive database records. The vulnerability also impacts site availability. Update to a version newer than 2.2.4.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site database and cause partial service disruption.
Potential impact on your site
04Site Impact
A compromised admin account could expose customer data, orders, or configuration stored in your database.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin or equivalent privileges on the site.
Key dates
06Disclosure timeline
March 13, 2026
CVE published
April 29, 2026
Record updated