CVE · High

CVE-2024-8271 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8271 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.2 Improper Control of Generation of Code ('Code Injection') High 7.3 < 1.4.2.2 1.4.2.2 2024-09-13

CVE-2024-8271

The FOX – Currency Switcher Professional for WooCommerce plugin has a security flaw affecting all versions prior to 1.4.2.1, allowing unauthorized execution of any shortcode due to an unchecked input value being fed into the do_shortcode function within the 'woocs_get_custom_price_html' process. This weakness can be exploited by unauthenticated individuals.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.