CVE Database /
CVE-2021-24938
CVE · Medium
CVE-2021-24938 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24938
|
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 1.3.7.1
|
1.3.7.1 |
2021-11-08 |
—
|
CVE-2021-24938
The WooCommerce Currency Switcher plugin prior to version 1.3.7.1 fails to properly sanitize and escape the key parameter in the woocs_update_profiles_data AJAX action, which any authenticated user can access. This oversight allows attackers to inject malicious scripts that are reflected back in the response, creating a reflected cross-site scripting vulnerability. The flaw affects all versions before 1.3.7.1 and is resolved in that version and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings