
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Security & Risk Analysis
wordpress.org/plugins/upsell-order-bump-offer-for-woocommerceUpsell Funnel Builder lets you create WooCommerce Upsells, Order Bumps, One Click upsell, Cross-Sells, Frequently Bought, and Popups.
Is Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Safe to Use in 2026?
Generally Safe
Score 98/100Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. has a strong security track record. Known vulnerabilities have been patched promptly.
The "upsell-order-bump-offer-for-woocommerce" plugin, version 3.1.2, presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output, a significant concern lies in its attack surface. The plugin exposes a large number of AJAX handlers (53 in total), with a concerning 51 of them lacking authentication checks. This widespread lack of authorization on AJAX endpoints represents a substantial risk, potentially allowing unauthenticated users to trigger sensitive plugin functionality.
The plugin's vulnerability history shows two previously disclosed medium-severity vulnerabilities, both related to Cross-site Scripting and External Control of Assumed-Immutable Web Parameters. While there are currently no unpatched vulnerabilities, the recurring nature of these vulnerability types might indicate recurring patterns in how user input is handled or how parameters are managed. The taint analysis, while not revealing critical or high severity flows, did identify six flows with unsanitized paths, which, combined with the unauthenticated AJAX handlers, could still lead to exploitable scenarios if not carefully reviewed.
In conclusion, the plugin benefits from strong SQL and output sanitization practices. However, the high number of unauthenticated AJAX endpoints is a critical weakness that significantly elevates the risk profile. The historical vulnerability pattern, though currently patched, warrants attention. Addressing the unauthenticated AJAX handlers should be the top priority to mitigate the most immediate and impactful security risks.
Key Concerns
- Large number of unprotected AJAX handlers
- Taint flows with unsanitized paths identified
- Past medium severity vulnerabilities (XSS, External Control)
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Upsell Order Bump Offer for WooCommerce <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Upsell Funnel Builder for WooCommerce <= 3.0.0 - Unauthenticated Order Manipulation
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Attack Surface
AJAX Handlers 53
Shortcodes 20
WordPress Hooks 121
Scheduled Events 1
Maintenance & Trust
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Maintenance & Trust
Maintenance Signals
Community Trust
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Alternatives
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
WPFunnels is a powerful funnel builder for WooCommerce that helps store owners create high-converting WooCommerce checkout pages, sales funnels, one-c …
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
Advanced Popups
advanced-popups
Display high-converting newsletter popups, a cookie notice, or a notification with the light-weight yet feature-rich plugin.
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. Developer Profile
13 plugins · 43K total installs
How We Detect Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/js/custom_woo_extra_checkout_fields.js/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/js/admin_custom_js.js/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/css/admin_custom_style.css/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/css/custom_woo_extra_checkout_fields.css/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/js/custom_woo_extra_checkout_fields.js/wp-content/plugins/upsell-order-bump-offer-for-woocommerce/js/admin_custom_js.jsupsell-order-bump-offer-for-woocommerce/js/custom_woo_extra_checkout_fields.js?ver=upsell-order-bump-offer-for-woocommerce/js/admin_custom_js.js?ver=upsell-order-bump-offer-for-woocommerce/css/admin_custom_style.css?ver=upsell-order-bump-offer-for-woocommerce/css/custom_woo_extra_checkout_fields.css?ver=HTML / DOM Fingerprints
wps_buy_now_funnel_buttonwps_buy_now_funnel_button_classwps_buy_now_add_to_cart_btnwps_buy_now_add_to_cart_btn_classwps_buy_now_add_to_cart_btn_add_cart_btnwps_buy_now_add_to_cart_btn_class_add_cart_btnwps_woo_bundle_option_value_displaywps_woo_bundle_option_value_display_class+2 more<!-- Start:Upsell Order Bump Offer For Woocommerce--><!-- End:Upsell Order Bump Offer For Woocommerce-->data-upsell-redirectdata-upsell-productdata-upsell-pricewps_wocuf_order_bump_object