Executive brief
The WordPress Currency Switcher (WPCS) plugin, used to enable multiple currency display on WordPress stores and websites, contains an unauthenticated cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into affected websites through this flaw, potentially stealing visitor data, hijacking user accounts, or defacing pages without requiring any authentication or special privileges.
Technical details
This is a stored or reflected cross-site scripting (XSS) vulnerability in the WPCS plugin versions 1.3.2 and earlier. The vulnerability allows unauthenticated attackers to inject arbitrary JavaScript code that executes in visitors' browsers. Exploitation requires user interaction such as clicking a malicious link or visiting a crafted page. The vulnerability is rooted in insufficient input validation and output encoding. An attacker can leverage this to steal session cookies, hijack visitor accounts, capture form data, or perform actions on behalf of authenticated users. The vulnerability has been patched in version 1.3.3 and later.
Affected products
- PluginUs.Net WPCS 1.3.2 and earlier
Timeline
- 2026-09-10: disclosed
- 2026-09-09: patched: Fixed in version 1.3.3
- 2026-08-24: reported