FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 - Unauthenticated Stored Cross-Site Scripting
high
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 7.2
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Jun 25, 2026
CVE-2026-57319 on NVD →
FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter
medium
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled `$_REQUEST['wooc_or...
- CVSS:
- 4.3
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- May 27, 2026
CVE-2026-9241 on NVD →
FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion
high
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, t...
- CVSS:
- 8.1
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- May 14, 2026
CVE-2026-4094 on NVD →
FOX <= 1.4.5 - Missing Authorization
medium
The FOX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Mar 27, 2026
CVE-2026-39501 on NVD →
FOX <= 1.4.5 - Authenticated (Shop manager+) SQL Injection
medium
The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to a...
- CVSS:
- 4.9
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Mar 23, 2026
CVE-2026-39497 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.3
unknown
[en] The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This m...
- Affected:
- up to 1.4.2.3
- Fixed in:
- 1.4.2.3
- Disclosed:
- Nov 9, 2024
CVE-2024-10640 on NVD →
The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution
high
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes...
- CVSS:
- 7.3
- Affected:
- up to 1.4.2.2
- Fixed in:
- 1.4.2.3
- Disclosed:
- Nov 8, 2024
CVE-2024-10640 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1
unknown
[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
- Affected:
- up to 1.4.2.1
- Fixed in:
- 1.4.2.1
- Disclosed:
- Nov 1, 2024
CVE-2024-43297 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.2
unknown
[en] The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the...
- Affected:
- up to 1.4.2.2
- Fixed in:
- 1.4.2.2
- Disclosed:
- Sep 14, 2024
CVE-2024-8271 on NVD →
FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution
high
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the 'wooc...
- CVSS:
- 7.3
- Affected:
- up to 1.4.2.1
- Fixed in:
- 1.4.2.2
- Disclosed:
- Sep 13, 2024
CVE-2024-8271 on NVD →
WOOCS – WooCommerce Currency Switcher <= 1.4.2 - Missing Authorization
medium
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_woocs_admin_theme_id AJAX action in versions up to, and including, 1.4.2. This makes it possible for authenticated attackers, with subscriber-level access an...
- CVSS:
- 4.3
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2.1
- Disclosed:
- Aug 16, 2024
CVE-2024-43297 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9
unknown
[en] The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installe...
- Affected:
- up to 1.4.1.9
- Fixed in:
- 1.4.1.9
- Disclosed:
- May 2, 2024
CVE-2024-3734 on NVD →
FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution
medium
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed and...
- CVSS:
- 6.5
- Affected:
- up to 1.4.1.8
- Fixed in:
- 1.4.1.9
- Disclosed:
- Apr 24, 2024
CVE-2024-3734 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.
- Affected:
- up to 1.4.1.8
- Fixed in:
- 1.4.1.8
- Disclosed:
- Mar 29, 2024
CVE-2024-30458 on NVD →
WOOCS – WooCommerce Currency Switcher <= 1.4.1.7 - Cross-Site Request Forgery
medium
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.7. This is due to missing or incorrect nonce validation on the save_etalon() function.. This makes it possible for unauthenticated attackers to update plugin settings via a...
- CVSS:
- 4.3
- Affected:
- up to 1.4.1.7
- Fixed in:
- 1.4.1.8
- Disclosed:
- Mar 28, 2024
CVE-2024-30458 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1
unknown
[en] The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
- Affected:
- up to 1.3.7.1
- Fixed in:
- 1.3.7.1
- Disclosed:
- Jan 16, 2024
CVE-2021-24566 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.7
unknown
[en] The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscrib...
- Affected:
- up to 1.4.1.7
- Fixed in:
- 1.4.1.7
- Disclosed:
- Jan 11, 2024
CVE-2023-6556 on NVD →
FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-le...
- CVSS:
- 5.4
- Affected:
- up to 1.4.1.6
- Fixed in:
- 1.4.1.7
- Disclosed:
- Dec 23, 2023
CVE-2023-6556 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
- Affected:
- up to 1.4.1.5
- Fixed in:
- 1.4.1.5
- Disclosed:
- Dec 17, 2023
CVE-2023-49834 on NVD →
WOOCS – WooCommerce Currency Switcher <= 1.4.1.4 - Cross-Site Request Forgery via delete_profiles_data
medium
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.4. This is due to missing or incorrect nonce validation on the delete_profiles_data function. This makes it possible for unauthenticated attackers to delete profile data via...
- CVSS:
- 5.4
- Affected:
- up to 1.4.1.4
- Fixed in:
- 1.4.1.5
- Disclosed:
- Dec 5, 2023
CVE-2023-49834 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.4
unknown
[en] The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
- Affected:
- up to 1.3.9.4
- Fixed in:
- 1.3.9.4
- Disclosed:
- Jan 16, 2023
CVE-2022-4431 on NVD →
WOOCS <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 1.3.9.2
- Fixed in:
- 1.3.9.3
- Disclosed:
- Dec 20, 2022
CVE-2022-4431 on NVD →
WOOCS <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 1.3.9.3
- Fixed in:
- 1.3.9.4
- Disclosed:
- Dec 20, 2022
CVE-2022-4431 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.3
unknown
Update the Wordpress WOOCS plugin to the latest available version (at least 1.3.9.3).
Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WOOCS – WooCommerce Currency Switcher Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertiseme...
- Affected:
- up to 1.3.9.3
- Fixed in:
- 1.3.9.3
- Disclosed:
- Dec 20, 2022
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.5
unknown
[en] The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.3.7.5
- Fixed in:
- 1.3.7.5
- Disclosed:
- Feb 21, 2022
CVE-2022-0234 on NVD →
WOOCS <= 1.3.7.4 - Reflected Cross-Site Scripting via AJAX action
medium
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 1.3.7.4
- Fixed in:
- 1.3.7.5
- Disclosed:
- Jan 19, 2022
CVE-2022-0234 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.3
unknown
[en] The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.3.7.3
- Fixed in:
- 1.3.7.3
- Disclosed:
- Jan 10, 2022
CVE-2021-25043 on NVD →
WOOCS <= 1.3.7.2 - Reflected Cross-Site Scripting
medium
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.3.7.2
- Fixed in:
- 1.3.7.3
- Disclosed:
- Dec 13, 2021
CVE-2021-25043 on NVD →
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1
unknown
[en] The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
- Affected:
- up to 1.3.7.1
- Fixed in:
- 1.3.7.1
- Disclosed:
- Dec 6, 2021
CVE-2021-24938 on NVD →
WooCommerce Currency Switcher <= 1.3.7 - Reflected Cross-Site Scripting
medium
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7.1
- Disclosed:
- Nov 8, 2021
CVE-2021-24938 on NVD →
WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 - Authenticated Local File Inclusion
high
The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7 via the "woocs.php" file. This allows low-level authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...
- CVSS:
- 8.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7.1
- Disclosed:
- Jul 22, 2021
CVE-2021-24566 on NVD →