CVE · Medium

CVE-2024-3734 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3734 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9 Improper Control of Generation of Code ('Code Injection') Medium 6.5 < 1.4.1.9 1.4.1.9 2024-04-24

CVE-2024-3734

The woocommerce-currency-switcher plugin before version 1.4.1.9 contains a flaw that permits unauthenticated users to run arbitrary shortcodes on affected sites. An attacker without credentials could exploit this vulnerability to execute shortcodes, with the potential impact varying based on what additional plugins are present and what shortcode capabilities they expose. This vulnerability affects all versions up through 1.4.1.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.