Extension WordPress
Vulnérabilités FOX – Currency Switcher Professional for WooCommerce
Cette page rassemble les failles publiées pour FOX – Currency Switcher Professional for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de FOX – Currency Switcher Professional for WooCommerce
18 fiches
FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 – Unauthenticated Stored Cross-Site Scripting
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.4.8
1.4.9
25/06/2026
FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 – Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the…
*-1.4.6
1.4.7
27/05/2026
FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 – Missing Authorization to Authenticated (Contributor+) Configuration Deletion
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it…
*-1.4.5
1.4.6
14/05/2026
FOX <= 1.4.5 – Missing Authorization
The FOX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-1.4.5
1.4.6
27/03/2026
FOX <= 1.4.5 – Authenticated (Shop manager+) SQL Injection
The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-1.4.5
1.4.6
23/03/2026
The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 – Unauthenticated Arbitrary Shortcode Execution
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action…
*-1.4.2.2
1.4.2.3
08/11/2024
FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 – Unauthenticated Arbitrary Shortcode Execution
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action…
*-1.4.2.1
1.4.2.2
13/09/2024
WOOCS – WooCommerce Currency Switcher <= 1.4.2 – Missing Authorization
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_woocs_admin_theme_id AJAX action in versions up to, and including, 1.4.2. This makes it possible…
*-1.4.2
1.4.2.1
16/08/2024
FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 – Unauthenticated Arbitrary Shortcode Execution
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what…
*-1.4.1.8
1.4.1.9
24/04/2024
WOOCS – WooCommerce Currency Switcher <= 1.4.1.7 – Cross-Site Request Forgery
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.7. This is due to missing or incorrect nonce validation on the save_etalon() function.. This makes it…
*-1.4.1.7
1.4.1.8
28/03/2024
FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes…
*-1.4.1.6
1.4.1.7
23/12/2023
WOOCS – WooCommerce Currency Switcher <= 1.4.1.4 – Cross-Site Request Forgery via delete_profiles_data
The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.4. This is due to missing or incorrect nonce validation on the delete_profiles_data function. This makes it…
*-1.4.1.4
1.4.1.5
05/12/2023
WOOCS <= 1.3.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…
*-1.3.9.3
1.3.9.4
20/12/2022
WOOCS <= 1.3.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…
*-1.3.9.2
1.3.9.3
20/12/2022
WOOCS <= 1.3.7.4 – Reflected Cross-Site Scripting via AJAX action
The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site…
*-1.3.7.4
1.3.7.5
19/01/2022
WOOCS <= 1.3.7.2 – Reflected Cross-Site Scripting
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
*-1.3.7.2
1.3.7.3
13/12/2021
WooCommerce Currency Switcher <= 1.3.7 – Reflected Cross-Site Scripting
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
*-1.3.7
1.3.7.1
08/11/2021
WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 – Authenticated Local File Inclusion
The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7 via the "woocs.php" file. This allows low-level authenticated attackers to include and execute arbitrary files on the server,…
*-1.3.7
1.3.7.1
22/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.