CVE · High

CVE-2024-13320 — WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.3.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13320 WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.3.7 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 2.3.7 2.3.7 2025-03-06

CVE-2024-13320

The WooCommerce Multi Currency plugin for WordPress has a security flaw that allows attackers to inject malicious SQL code into the system. This vulnerability occurs when the plugin does not properly sanitize user input in a specific parameter, allowing attackers to inject their own SQL queries. As a result, attackers can potentially extract sensitive information from the database without needing to authenticate.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.