Junglewise Threat Intelligence

CVE-2026-39497: RealMag777 FOX woocommerce-currency-switcher SQL Injection

CVE-2026-39497 · Severity: high · CVSS 7.6 · Published 2026-04-08

Executive brief

FOX (formerly WooCommerce Currency Switcher) is a popular WordPress plugin used by online stores to display prices and accept payments in multiple currencies. A security vulnerability in this plugin could allow an attacker with high-level administrative access (such as a Shop Manager) to perform unauthorized database queries. This could lead to the exposure of sensitive store data, including customer information and site configuration details.

Technical details

A Blind SQL Injection vulnerability exists in the RealMag777 FOX woocommerce-currency-switcher plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw allows an authenticated attacker with 'Shop Manager' or higher privileges to execute arbitrary SQL queries against the backend database via network requests. By leveraging blind injection techniques, an attacker can exfiltrate sensitive data such as user hashes or configuration settings. The vulnerability is present in versions up to and including 1.4.5 and has been addressed in version 1.4.6.

Affected products

  • RealMag777 (PluginUs.Net) FOX woocommerce-currency-switcher <= 1.4.5

Timeline

  • 2026-02-21: other: Vulnerability reported by researcher timomangcut
  • 2026-03-23: advisory: Initial disclosure by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-03-23: patched: Version 1.4.6 released to address the issue

References