Executive brief
The CURCY plugin for WooCommerce, which allows online stores to display prices in multiple currencies, contains a security flaw that allows users to execute arbitrary shortcodes. This could allow an attacker to access sensitive information or perform unauthorized actions by triggering internal WordPress functions that are normally restricted. The issue affects all versions of the plugin up to 2.2.14.
Technical details
The CURCY plugin for WordPress is vulnerable to arbitrary shortcode execution due to the application failing to properly validate user-supplied input before passing it to the WordPress 'do_shortcode' function. This vulnerability is located within the frontend cache handling logic (specifically in cache.php). An attacker with subscriber-level permissions (or potentially unauthenticated, though CVSS indicates Low Privilege) can exploit this to execute any shortcode available on the site. This can lead to information disclosure or further exploitation depending on the other plugins installed. The vulnerability affects all versions up to and including 2.2.14.
Affected products
- VillaTheme CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x Up to, and including, 2.2.14
Timeline
- 2026-07-03: disclosed: Initial publication of the CVE advisory
References
- https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php
- https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php
- https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5a30e5dc-1f15-40ce-9703-1e1add1df6da?source=cve