CVE · High

CVE-2026-39497 — FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39497 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6 High 7.6 < 1.4.6 1.4.6 2026-03-23

CVE-2026-39497

The FOX plugin for WordPress contains a security flaw in versions 1.4.5 and earlier, where user input is not properly sanitized, allowing malicious users with elevated permissions to inject unauthorized SQL code into database queries. This vulnerability enables attackers to access sensitive data by appending additional SQL commands to existing queries. Affected users can expect unauthorized information extraction from the database as a result of this flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.