Junglewise Threat Intelligence

CVE-2026-84816: WordPress WPCS plugin unauthenticated XSS

CVE-2026-84816 · Severity: high · CVSS 7.1 · Published 2026-09-10

Vendors: PluginUs.Net.

Executive brief

The WordPress Currency Switcher (WPCS) plugin, used to enable multiple currency display on WordPress stores and websites, contains an unauthenticated cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into affected websites through this flaw, potentially stealing visitor data, hijacking user accounts, or defacing pages without requiring any authentication or special privileges.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in the WPCS plugin versions 1.3.2 and earlier. The vulnerability allows unauthenticated attackers to inject arbitrary JavaScript code that executes in visitors' browsers. Exploitation requires user interaction such as clicking a malicious link or visiting a crafted page. The vulnerability is rooted in insufficient input validation and output encoding. An attacker can leverage this to steal session cookies, hijack visitor accounts, capture form data, or perform actions on behalf of authenticated users. The vulnerability has been patched in version 1.3.3 and later.

Affected products

  • PluginUs.Net WPCS 1.3.2 and earlier

Timeline

  • 2026-09-10: disclosed
  • 2026-09-09: patched: Fixed in version 1.3.3
  • 2026-08-24: reported

References