CVE Database /
CVE-2024-3734
CVE · Medium
CVE-2024-3734 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3734
|
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9 |
Improper Control of Generation of Code ('Code Injection') |
Medium
6.5
|
< 1.4.1.9
|
1.4.1.9 |
2024-04-24 |
—
|
CVE-2024-3734
The woocommerce-currency-switcher plugin before version 1.4.1.9 contains a flaw that permits unauthenticated users to run arbitrary shortcodes on affected sites. An attacker without credentials could exploit this vulnerability to execute shortcodes, with the potential impact varying based on what additional plugins are present and what shortcode capabilities they expose. This vulnerability affects all versions up through 1.4.1.8.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings