plugin

Woocommerce Currency Switcher Vulnerabilities

31 known security issues reported for the Woocommerce Currency Switcher WordPress plugin. Most recent disclosed Jun 25, 2026.

5 high 13 medium

Running Woocommerce Currency Switcher on your site? Check whether your installed version is affected.

Scan your site free

FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 - Unauthenticated Stored Cross-Site Scripting

high

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
7.2
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
Jun 25, 2026

CVE-2026-57319 on NVD →

FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter

medium

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled `$_REQUEST['wooc_or...

CVSS:
4.3
Affected:
up to 1.4.6
Fixed in:
1.4.7
Disclosed:
May 27, 2026

CVE-2026-9241 on NVD →

FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion

high

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
8.1
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
May 14, 2026

CVE-2026-4094 on NVD →

FOX <= 1.4.5 - Missing Authorization

medium

The FOX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
Mar 27, 2026

CVE-2026-39501 on NVD →

FOX <= 1.4.5 - Authenticated (Shop manager+) SQL Injection

medium

The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to a...

CVSS:
4.9
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
Mar 23, 2026

CVE-2026-39497 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.3

unknown

[en] The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This m...

Affected:
up to 1.4.2.3
Fixed in:
1.4.2.3
Disclosed:
Nov 9, 2024

CVE-2024-10640 on NVD →

The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution

high

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes...

CVSS:
7.3
Affected:
up to 1.4.2.2
Fixed in:
1.4.2.3
Disclosed:
Nov 8, 2024

CVE-2024-10640 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1

unknown

[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.

Affected:
up to 1.4.2.1
Fixed in:
1.4.2.1
Disclosed:
Nov 1, 2024

CVE-2024-43297 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.2

unknown

[en] The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the...

Affected:
up to 1.4.2.2
Fixed in:
1.4.2.2
Disclosed:
Sep 14, 2024

CVE-2024-8271 on NVD →

FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution

high

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the 'wooc...

CVSS:
7.3
Affected:
up to 1.4.2.1
Fixed in:
1.4.2.2
Disclosed:
Sep 13, 2024

CVE-2024-8271 on NVD →

WOOCS – WooCommerce Currency Switcher <= 1.4.2 - Missing Authorization

medium

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_woocs_admin_theme_id AJAX action in versions up to, and including, 1.4.2. This makes it possible for authenticated attackers, with subscriber-level access an...

CVSS:
4.3
Affected:
up to 1.4.2
Fixed in:
1.4.2.1
Disclosed:
Aug 16, 2024

CVE-2024-43297 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9

unknown

[en] The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installe...

Affected:
up to 1.4.1.9
Fixed in:
1.4.1.9
Disclosed:
May 2, 2024

CVE-2024-3734 on NVD →

FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution

medium

The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed and...

CVSS:
6.5
Affected:
up to 1.4.1.8
Fixed in:
1.4.1.9
Disclosed:
Apr 24, 2024

CVE-2024-3734 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.

Affected:
up to 1.4.1.8
Fixed in:
1.4.1.8
Disclosed:
Mar 29, 2024

CVE-2024-30458 on NVD →

WOOCS – WooCommerce Currency Switcher <= 1.4.1.7 - Cross-Site Request Forgery

medium

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.7. This is due to missing or incorrect nonce validation on the save_etalon() function.. This makes it possible for unauthenticated attackers to update plugin settings via a...

CVSS:
4.3
Affected:
up to 1.4.1.7
Fixed in:
1.4.1.8
Disclosed:
Mar 28, 2024

CVE-2024-30458 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1

unknown

[en] The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Affected:
up to 1.3.7.1
Fixed in:
1.3.7.1
Disclosed:
Jan 16, 2024

CVE-2021-24566 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.7

unknown

[en] The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscrib...

Affected:
up to 1.4.1.7
Fixed in:
1.4.1.7
Disclosed:
Jan 11, 2024

CVE-2023-6556 on NVD →

FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-le...

CVSS:
5.4
Affected:
up to 1.4.1.6
Fixed in:
1.4.1.7
Disclosed:
Dec 23, 2023

CVE-2023-6556 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.

Affected:
up to 1.4.1.5
Fixed in:
1.4.1.5
Disclosed:
Dec 17, 2023

CVE-2023-49834 on NVD →

WOOCS – WooCommerce Currency Switcher <= 1.4.1.4 - Cross-Site Request Forgery via delete_profiles_data

medium

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.4. This is due to missing or incorrect nonce validation on the delete_profiles_data function. This makes it possible for unauthenticated attackers to delete profile data via...

CVSS:
5.4
Affected:
up to 1.4.1.4
Fixed in:
1.4.1.5
Disclosed:
Dec 5, 2023

CVE-2023-49834 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.4

unknown

[en] The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Affected:
up to 1.3.9.4
Fixed in:
1.3.9.4
Disclosed:
Jan 16, 2023

CVE-2022-4431 on NVD →

WOOCS <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 1.3.9.2
Fixed in:
1.3.9.3
Disclosed:
Dec 20, 2022

CVE-2022-4431 on NVD →

WOOCS <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 1.3.9.3
Fixed in:
1.3.9.4
Disclosed:
Dec 20, 2022

CVE-2022-4431 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.3

unknown

Update the Wordpress WOOCS plugin to the latest available version (at least 1.3.9.3). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WOOCS – WooCommerce Currency Switcher Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertiseme...

Affected:
up to 1.3.9.3
Fixed in:
1.3.9.3
Disclosed:
Dec 20, 2022

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.5

unknown

[en] The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.3.7.5
Fixed in:
1.3.7.5
Disclosed:
Feb 21, 2022

CVE-2022-0234 on NVD →

WOOCS <= 1.3.7.4 - Reflected Cross-Site Scripting via AJAX action

medium

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 1.3.7.4
Fixed in:
1.3.7.5
Disclosed:
Jan 19, 2022

CVE-2022-0234 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.3

unknown

[en] The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.3.7.3
Fixed in:
1.3.7.3
Disclosed:
Jan 10, 2022

CVE-2021-25043 on NVD →

WOOCS <= 1.3.7.2 - Reflected Cross-Site Scripting

medium

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.3.7.2
Fixed in:
1.3.7.3
Disclosed:
Dec 13, 2021

CVE-2021-25043 on NVD →

FOX &#8211; Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1

unknown

[en] The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

Affected:
up to 1.3.7.1
Fixed in:
1.3.7.1
Disclosed:
Dec 6, 2021

CVE-2021-24938 on NVD →

WooCommerce Currency Switcher <= 1.3.7 - Reflected Cross-Site Scripting

medium

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.3.7
Fixed in:
1.3.7.1
Disclosed:
Nov 8, 2021

CVE-2021-24938 on NVD →

WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 - Authenticated Local File Inclusion

high

The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7 via the "woocs.php" file. This allows low-level authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...

CVSS:
8.8
Affected:
up to 1.3.7
Fixed in:
1.3.7.1
Disclosed:
Jul 22, 2021

CVE-2021-24566 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database