CVE · High

CVE-2024-43297 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43297 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1 Missing Authorization High 8.8 < 1.4.2.1 1.4.2.1 2024-08-16

CVE-2024-43297

The WOOCS – WooCommerce Currency Switcher plugin up to version 1.4.2 contains a vulnerability where the wp_ajax_woocs_admin_theme_id AJAX function fails to properly verify user capabilities before processing requests. This flaw allows any logged-in user with subscriber privileges or higher to modify the theme ID setting without proper authorization. Attackers can exploit this weakness to alter plugin configuration data by making unauthorized AJAX calls.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.