Extension WordPress

Vulnérabilités FOX – Currency Switcher Professional for WooCommerce

Cette page rassemble les failles publiées pour FOX – Currency Switcher Professional for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

18Vulnérabilités
0Critiques
18Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FOX – Currency Switcher Professional for WooCommerce

18 fiches

CVE-2026-57319 Élevée · 7,2
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 – Unauthenticated Stored Cross-Site Scripting

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.4.8

Correctif

1.4.9

Publication

25/06/2026

CVE-2026-9241 Moyenne · 4,3
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 – Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the…

Versions affectées

*-1.4.6

Correctif

1.4.7

Publication

27/05/2026

CVE-2026-4094 Élevée · 8,1
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 – Missing Authorization to Authenticated (Contributor+) Configuration Deletion

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it…

Versions affectées

*-1.4.5

Correctif

1.4.6

Publication

14/05/2026

CVE-2024-10640 Élevée · 7,3
FOX – Currency Switcher Professional for WooCommerce

The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 – Unauthenticated Arbitrary Shortcode Execution

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action…

Versions affectées

*-1.4.2.2

Correctif

1.4.2.3

Publication

08/11/2024

CVE-2024-8271 Élevée · 7,3
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 – Unauthenticated Arbitrary Shortcode Execution

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action…

Versions affectées

*-1.4.2.1

Correctif

1.4.2.2

Publication

13/09/2024

CVE-2024-43297 Moyenne · 4,3
FOX – Currency Switcher Professional for WooCommerce

WOOCS – WooCommerce Currency Switcher <= 1.4.2 – Missing Authorization

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_woocs_admin_theme_id AJAX action in versions up to, and including, 1.4.2. This makes it possible…

Versions affectées

*-1.4.2

Correctif

1.4.2.1

Publication

16/08/2024

CVE-2024-3734 Moyenne · 6,5
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 – Unauthenticated Arbitrary Shortcode Execution

The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what…

Versions affectées

*-1.4.1.8

Correctif

1.4.1.9

Publication

24/04/2024

CVE-2024-30458 Moyenne · 4,3
FOX – Currency Switcher Professional for WooCommerce

WOOCS – WooCommerce Currency Switcher <= 1.4.1.7 – Cross-Site Request Forgery

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.7. This is due to missing or incorrect nonce validation on the save_etalon() function.. This makes it…

Versions affectées

*-1.4.1.7

Correctif

1.4.1.8

Publication

28/03/2024

CVE-2023-6556 Moyenne · 5,4
FOX – Currency Switcher Professional for WooCommerce

FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.4.1.6

Correctif

1.4.1.7

Publication

23/12/2023

CVE-2023-49834 Moyenne · 5,4
FOX – Currency Switcher Professional for WooCommerce

WOOCS – WooCommerce Currency Switcher <= 1.4.1.4 – Cross-Site Request Forgery via delete_profiles_data

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.4. This is due to missing or incorrect nonce validation on the delete_profiles_data function. This makes it…

Versions affectées

*-1.4.1.4

Correctif

1.4.1.5

Publication

05/12/2023

CVE-2022-4431 Moyenne · 6,4
FOX – Currency Switcher Professional for WooCommerce

WOOCS <= 1.3.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…

Versions affectées

*-1.3.9.3

Correctif

1.3.9.4

Publication

20/12/2022

CVE-2022-4431 Moyenne · 6,4
FOX – Currency Switcher Professional for WooCommerce

WOOCS <= 1.3.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…

Versions affectées

*-1.3.9.2

Correctif

1.3.9.3

Publication

20/12/2022

CVE-2022-0234 Moyenne · 6,1
FOX – Currency Switcher Professional for WooCommerce

WOOCS <= 1.3.7.4 – Reflected Cross-Site Scripting via AJAX action

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site…

Versions affectées

*-1.3.7.4

Correctif

1.3.7.5

Publication

19/01/2022

CVE-2021-24938 Moyenne · 6,1
FOX – Currency Switcher Professional for WooCommerce

WooCommerce Currency Switcher <= 1.3.7 – Reflected Cross-Site Scripting

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

Versions affectées

*-1.3.7

Correctif

1.3.7.1

Publication

08/11/2021

CVE-2021-24566 Élevée · 8,8
FOX – Currency Switcher Professional for WooCommerce

WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 – Authenticated Local File Inclusion

The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7 via the "woocs.php" file. This allows low-level authenticated attackers to include and execute arbitrary files on the server,…

Versions affectées

*-1.3.7

Correctif

1.3.7.1

Publication

22/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités