Executive brief
The FOX Currency Switcher plugin for WooCommerce is vulnerable to a security flaw that allows low-level users to delete the website's entire multi-currency configuration. This plugin is used by online stores to display prices in different currencies; an exploit would disrupt the shopping experience and require manual restoration of currency settings. The attack can be carried out by anyone with a basic account on the site or by tricking an administrator into clicking a malicious link.
Technical details
The vulnerability stems from a missing capability check and a lack of nonce verification in the 'admin_head' function within the FOX Currency Switcher plugin. Authenticated attackers with Contributor-level access (or Subscriber-level if wp-admin access is enabled) can trigger a reset of the multi-currency configuration by appending the 'woocs_reset' parameter to any administrative page URL. Additionally, the absence of a CSRF nonce makes the function exploitable via Cross-Site Request Forgery, allowing an unauthenticated attacker to achieve the same result by tricking a logged-in administrator into visiting a crafted URL. The issue is fixed in versions following 1.4.5.
Affected products
- RealMag777 FOX – Currency Switcher Professional for WooCommerce Up to, and including, 1.4.5
Timeline
- 2026-05-15: disclosed
- 2026-05-15: advisory
References
- https://plugins.trac.wordpress.org/browser/woocommerce-currency-switcher/trunk/classes/woocs.php
- https://plugins.trac.wordpress.org/browser/woocommerce-currency-switcher/trunk/classes/woocs.php
- https://plugins.trac.wordpress.org/changeset/3483839/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6eb9d68c-c081-484e-ad5d-5eabcfa6d6f0?source=cve