PLUGIN SECURITY

Is CURCY - WooCommerce Multi Currency Premium safe?

Show multi-currency pricing and dual-currency display, accept multi-currency payment, support IP detection, custom/global rate, fixed price and more

What this plugin does

  • Slug: woocommerce-multi-currency
  • Author: VillaTheme
  • 20000+ active installs
  • 86/100 rating (226 reviews on wordpress.org)
  • 1110909 all-time downloads
  • On WordPress.org since 2016-03-25

ecommercemulti currency for woowoocommercewoocommerce currency switcherwoocommerce multi currency

Maintenance status

  • Last updated: 2026-08-22 9:08am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+

Known vulnerabilities

4 known CVEs on file for CURCY - WooCommerce Multi Currency Premium. Reported between 2021 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] <= 2.3.7 (unfixed) Missing Authorization Medium 5.3 < 2.3.7 2.3.7 2025-05-16
CVE-2024-13320 WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.3.7 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 2.3.7 2.3.7 2025-03-06
CVE-2021-4376 WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.1.18 Missing Authorization Medium 4.3 < 2.1.18 2.1.18 2023-06-07
WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.1.18 Unknown < 2.1.18 2.1.18 2021-09-13
CVE-2021-4379 WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.1.18 Missing Authorization Medium 6.5 < 2.1.18 2.1.18 2021-09-13
WooCommerce Multi Currency - Currency Switcher [woocommerce-multi-currency] < 2.1.18 Unknown < 2.1.18 2.1.18
CVE-2025-47563 CURCY <= 2.3.7 - Missing Authorization to Arbitrary Shortcode Execution Unknown not specified no fix on file

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.