Executive brief
The FOX WooCommerce Currency Switcher plugin for WordPress, which allows online stores to display prices in multiple currencies, contains a security flaw in its access control settings. This vulnerability could allow an unauthorized person to access or perform actions that should be restricted to administrators or specific user roles. While the impact is considered moderate, it could lead to unauthorized data exposure or minor configuration changes depending on the specific site setup.
Technical details
A missing authorization vulnerability (CWE-862) exists in the RealMag777 FOX WooCommerce Currency Switcher plugin (formerly known as WOOCS) for WordPress. The flaw is rooted in incorrectly configured access control security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially bypassing intended permission checks to execute restricted actions or view sensitive information. The vulnerability is addressed in version 1.4.6.
Affected products
- RealMag777 FOX - WooCommerce Currency Switcher Professional <= 1.4.5
Timeline
- 2026-02-25: other: Reported by researcher Que Thanh Tuan
- 2026-03-27: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published to NVD
- 2026-04-08: patched: Patch released in version 1.4.6