Junglewise Threat Intelligence

CVE-2026-57319: RealMag777 FOX unauthenticated XSS in WooCommerce Currency Switcher

CVE-2026-57319 · Severity: high · CVSS 7.1 · Published 2026-06-26

Technologies: RealMag777 FOX – Currency Switcher Professional for WooCommerce. Vendors: RealMag777.

Executive brief

FOX (formerly WooCommerce Currency Switcher) is a WordPress plugin that allows e-commerce stores to display prices and accept payments in multiple currencies. A security vulnerability in versions 1.4.8 and earlier allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.

Technical details

The FOX (WooCommerce Currency Switcher) plugin for WordPress contains an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in versions up to 1.4.8. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking or unauthorized administrative actions if the victim is a site administrator. The issue is resolved in version 1.4.9.

Affected products

  • RealMag777 FOX - Currency Switcher Professional for WooCommerce <= 1.4.8

Timeline

  • 2026-06-08: disclosed: Reported by Nguyen Ba Khanh
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: advisory: NVD published CVE-2026-57319
  • 2026-06-26: patched: Version 1.4.9 released to address the vulnerability

References

Related threats