CVE-2026-9241
The FOX – Currency Switcher Professional for WooCommerce plugin on WordPress suffers from an authorization bypass vulnerability in versions up to 1.4.6. The vulnerability arises from the plugin trusting user-controlled input to determine a user's role for price resolution, allowing attackers to override their actual role and obtain prices intended for higher-privileged roles. This can be exploited by authenticated users with Subscriber-level access or higher to obtain discounted or restricted pricing. The issue is only exploitable when fixed user-role pricing is enabled and there is at least one product with a privileged-role price configured.
Based on public CVE data (MITRE/NVD).