PT-2024-10891 · WordPress · Currency Switcher For Woocommerce

Marc Montpas

·

Published

2024-01-16

·

Updated

2024-10-23

·

CVE-2021-24566

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Currency Switcher FOX WordPress plugin versions prior to 1.3.7
Description The issue concerns a Local File Inclusion (LFI) vulnerability. LFI is a type of attack where an attacker can trick the application into exposing or running files on the server that they shouldn't have access to. This vulnerability can be exploited via the woocs shortcode.
Recommendations For versions prior to 1.3.7, update to version 1.3.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the woocs shortcode until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-24566

Affected Products

Currency Switcher For Woocommerce