CVE · Medium

CVE-2021-24938 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24938 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.7.1 1.3.7.1 2021-11-08

CVE-2021-24938

The WooCommerce Currency Switcher plugin prior to version 1.3.7.1 fails to properly sanitize and escape the key parameter in the woocs_update_profiles_data AJAX action, which any authenticated user can access. This oversight allows attackers to inject malicious scripts that are reflected back in the response, creating a reflected cross-site scripting vulnerability. The flaw affects all versions before 1.3.7.1 and is resolved in that version and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.