Executive brief
The WPCS currency switcher plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user interacts with a specially crafted link or page, potentially leading to unauthorized actions being performed in the user's browser. Successful exploitation can result in website defacement, redirection to malicious sites, or the theft of sensitive session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the RealMag777 WPCS (WordPress Currency Switcher) plugin due to improper neutralization of input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious JavaScript into the Document Object Model (DOM) environment of a victim's browser. Exploitation requires a user to perform an action, such as clicking a malicious link (User Interaction: Required). This can lead to session hijacking, unauthorized administrative actions if the victim is an admin, or delivery of further browser-based exploits. The issue is resolved in version 1.3.2.
Affected products
- RealMag777 (PluginUs.Net) WPCS - WordPress Currency Switcher Professional <= 1.3.1
Timeline
- 2026-04-25: other: Reported by hhhai
- 2026-05-25: advisory: Patchstack advisory published
- 2026-05-27: disclosed: CVE published to NVD
- 2026-05-25: patched: Version 1.3.2 released