CVE · Medium

CVE-2019-18668 — Currency Switcher for WooCommerce [currency-switcher-woocommerce] < 2.11.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-18668 Currency Switcher for WooCommerce [currency-switcher-woocommerce] < 2.11.2 Improper Handling of Exceptional Conditions Medium 6.5 < 2.11.2 2.11.2 2019-11-02

CVE-2019-18668

The Currency Switcher addon for WooCommerce prior to version 2.11.2 contains a flaw where selecting a non-existent currency that an administrator has not configured allows the attacker to proceed with checkout while the system falls back to displaying prices in the default currency. An attacker can exploit this by choosing a non-existent currency with a lower value than the default, enabling them to complete purchases at substantially reduced prices.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.