Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wpwham Subscribe
Filtered by product Currency Switcher For Woocommerce
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18668 1 Wpwham 1 Currency Switcher For Woocommerce 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.