PLUGIN SECURITY

Is FOX – Currency Switcher Professional for WooCommerce safe?

FOX - Currency Switcher Professional for WooCommerce (former name is WOOCS) is currency plugin for woocommerce and multi currency shop, switch & pay

What this plugin does

  • Slug: woocommerce-currency-switcher
  • Author: RealMag777
  • 50000+ active installs
  • 88/100 rating (250 reviews on wordpress.org)
  • 2230723 all-time downloads
  • On WordPress.org since 2014-09-20

convertercurrencycurrency switcherswitcherwoocommerce

Maintenance status

  • Latest known version: 1.5.1
  • Last updated: 2026-07-27 10:06am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

17 known CVEs on file for FOX – Currency Switcher Professional for WooCommerce. Reported between 2021 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57319 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.4.9 1.4.9 2026-06-25 ✓ fixed in latest
CVE-2026-9241 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.7 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.4.7 1.4.7 2026-05-27 ✓ fixed in latest
CVE-2026-4094 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6 Missing Authorization High 8.1 < 1.4.6 1.4.6 2026-05-14 ✓ fixed in latest
CVE-2026-39501 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6 Medium 5.3 < 1.4.6 1.4.6 2026-03-27 ✓ fixed in latest
CVE-2026-39497 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6 High 7.6 < 1.4.6 1.4.6 2026-03-23 ✓ fixed in latest
CVE-2024-10640 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.3 Improper Control of Generation of Code ('Code Injection') High 7.3 < 1.4.2.3 1.4.2.3 2024-11-08 ✓ fixed in latest
CVE-2024-8271 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.2 Improper Control of Generation of Code ('Code Injection') High 7.3 < 1.4.2.2 1.4.2.2 2024-09-13 ✓ fixed in latest
CVE-2024-43297 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.2.1 Missing Authorization High 8.8 < 1.4.2.1 1.4.2.1 2024-08-16 ✓ fixed in latest
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3734 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.9 Improper Control of Generation of Code ('Code Injection') Medium 6.5 < 1.4.1.9 1.4.1.9 2024-04-24 ✓ fixed in latest
CVE-2024-30458 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.8 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.4.1.8 1.4.1.8 2024-03-28 ✓ fixed in latest
CVE-2023-6556 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.4.1.7 1.4.1.7 2023-12-23 ✓ fixed in latest
CVE-2023-49834 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.1.5 Cross-Site Request Forgery (CSRF) Medium 5.4 < 1.4.1.5 1.4.1.5 2023-12-05 ✓ fixed in latest
CVE-2022-4431 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.3.9.4 1.3.9.4 2022-12-20 ✓ fixed in latest
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.9.3 Unknown < 1.3.9.3 1.3.9.3 2022-12-20 ✓ fixed in latest
CVE-2022-0234 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.7.5 1.3.7.5 2022-01-19 ✓ fixed in latest
CVE-2021-25043 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.7.3 1.3.7.3 2021-12-13 ✓ fixed in latest
CVE-2021-24938 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.7.1 1.3.7.1 2021-11-08 ✓ fixed in latest
CVE-2021-24566 FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.3.7.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 1.3.7.1 1.3.7.1 2021-07-22 ✓ fixed in latest

How to fix it

Keep FOX – Currency Switcher Professional for WooCommerce updated — 1.5.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.