Pluginus
Pluginus FOX - Currency Switcher Professional FOR Woocommerce: vulnerabilities and CVEs
Pluginus FOX - Currency Switcher Professional FOR Woocommerce has 7 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8271 | High (7.3) | 0.74% | — | Sep 14, 2024 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users… |
| CVE-2024-3734 | Medium (6.5) | 1.0% | — | May 2, 2024 | The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute… |
| CVE-2024-30458 | High (8.8) | 0.24% | — | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7. |
| CVE-2021-24566 | High (8.8) | 1.3% | — | Jan 16, 2024 | The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode. |
| CVE-2023-6556 | Medium (5.4) | 0.41% | — | Jan 11, 2024 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input… |
| CVE-2023-49834 | High (8.8) | 0.25% | — | Dec 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4. |
| CVE-2022-4431 | Medium (5.4) | 0.50% | — | Jan 16, 2023 | The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform… |
Other products by Pluginus
Bear - Woocommerce Bulk Editor AND Products Manager Professional · 18Husky - Products Filter Professional FOR Woocommerce · 14Wordpress Meta Data AND Taxonomies Filter · 12Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional · 10Active Products Tables FOR Woocommerce · 9Woot · 7Inpost Gallery · 5Wordpress Currency Switcher · 3Wordpress Currency Switcher Professional · 3Bear · 2Meta Data AND Taxonomies Filter · 2Woocommerce Products Filter · 2