Junglewise Threat Intelligence

CVE-2026-4094: RealMag777 FOX Currency Switcher unauthorized data loss in admin_head

CVE-2026-4094 · Severity: high · CVSS 8.1 · Published 2026-05-15

Technologies: RealMag777 FOX – Currency Switcher Professional for WooCommerce. Vendors: RealMag777.

Executive brief

The FOX Currency Switcher plugin for WooCommerce is vulnerable to a security flaw that allows low-level users to delete the website's entire multi-currency configuration. This plugin is used by online stores to display prices in different currencies; an exploit would disrupt the shopping experience and require manual restoration of currency settings. The attack can be carried out by anyone with a basic account on the site or by tricking an administrator into clicking a malicious link.

Technical details

The vulnerability stems from a missing capability check and a lack of nonce verification in the 'admin_head' function within the FOX Currency Switcher plugin. Authenticated attackers with Contributor-level access (or Subscriber-level if wp-admin access is enabled) can trigger a reset of the multi-currency configuration by appending the 'woocs_reset' parameter to any administrative page URL. Additionally, the absence of a CSRF nonce makes the function exploitable via Cross-Site Request Forgery, allowing an unauthenticated attacker to achieve the same result by tricking a logged-in administrator into visiting a crafted URL. The issue is fixed in versions following 1.4.5.

Affected products

  • RealMag777 FOX – Currency Switcher Professional for WooCommerce Up to, and including, 1.4.5

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory

References

Related threats