CURCY <= 2.3.7 - Missing Authorization to Arbitrary Shortcode Execution
medium
The The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.3.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes...
- CVSS:
- 6.5
- Affected:
- up to 2.3.7
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-47563 on NVD →
CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection
high
The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...
- CVSS:
- 7.5
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.7
- Disclosed:
- Mar 6, 2025
CVE-2024-13320 on NVD →
WooCommerce Multi Currency <= 2.1.17 - Missing Authorization
medium
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to make changes to p...
- CVSS:
- 6.5
- Affected:
- up to 2.1.17
- Fixed in:
- 2.1.18
- Disclosed:
- Sep 13, 2021
CVE-2021-4379 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database