PT-2024-16426 · WordPress · Fox – Currency Switcher Professional

Michael Mazzolini

+1

·

Published

2024-11-09

·

Updated

2024-11-13

·

CVE-2024-10640

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress versions up to, and including, 1.4.2.2
Description The issue is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability affects multiple versions of the WooCommerce Currency Switcher plugin.
Recommendations Update to the latest version to secure your site. As a temporary workaround, consider restricting the execution of shortcodes to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-10640

Affected Products

Fox – Currency Switcher Professional