CVE-2024-8271
- EPSS 1.72%
- Veröffentlicht 14.09.2024 03:15:08
- Zuletzt bearbeitet 27.09.2024 16:21:38
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does ...
CVE-2024-3734
- EPSS 2.01%
- Veröffentlicht 02.05.2024 17:15:30
- Zuletzt bearbeitet 21.11.2024 09:30:16
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The sever...
CVE-2024-30458
- EPSS 0.17%
- Veröffentlicht 29.03.2024 13:15:14
- Zuletzt bearbeitet 09.04.2025 15:43:13
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.
CVE-2021-24566
- EPSS 1.8%
- Veröffentlicht 16.01.2024 16:15:09
- Zuletzt bearbeitet 11.06.2025 17:15:29
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
CVE-2023-6556
- EPSS 0.28%
- Veröffentlicht 11.01.2024 09:15:48
- Zuletzt bearbeitet 21.11.2024 08:44:05
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. ...
CVE-2023-49834
- EPSS 0.05%
- Veröffentlicht 17.12.2023 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:33:55
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
CVE-2022-4431
- EPSS 0.18%
- Veröffentlicht 16.01.2023 16:15:11
- Zuletzt bearbeitet 04.04.2025 21:15:42
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks ...