cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcurrency-switcher-woocommerce currency-switcher-woocommerce

Direction: ascending
Jun 06, 2024

Currency Switcher for WooCommerce # CVE-2019-18668

CVE, Research URL

CVE-2019-18668

Date
Nov 02, 2019
Research Description
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.
Affected versions
max 2.11.2.
Status
vulnerable
Mar 02, 2025

Currency Switcher for WooCommerce # CVE-2024-9217

CVE, Research URL

CVE-2024-9217

Date
Mar 01, 2025
Research Description
The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.16.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.16.3.
Status
vulnerable