CVE Database /
CVE-2026-39497
CVE · High
CVE-2026-39497 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39497
|
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6 |
— |
High
7.6
|
< 1.4.6
|
1.4.6 |
2026-03-23 |
—
|
CVE-2026-39497
The FOX plugin for WordPress contains a security flaw in versions 1.4.5 and earlier, where user input is not properly sanitized, allowing malicious users with elevated permissions to inject unauthorized SQL code into database queries. This vulnerability enables attackers to access sensitive data by appending additional SQL commands to existing queries. Affected users can expect unauthorized information extraction from the database as a result of this flaw.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings