CVE Database /
CVE-2024-43297
CVE · High
CVE-2024-43297 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43297
|
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1 |
Missing Authorization |
High
8.8
|
< 1.4.2.1
|
1.4.2.1 |
2024-08-16 |
—
|
CVE-2024-43297
The WOOCS – WooCommerce Currency Switcher plugin up to version 1.4.2 contains a vulnerability where the wp_ajax_woocs_admin_theme_id AJAX function fails to properly verify user capabilities before processing requests. This flaw allows any logged-in user with subscriber privileges or higher to modify the theme ID setting without proper authorization. Attackers can exploit this weakness to alter plugin configuration data by making unauthorized AJAX calls.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings