Missing Authorization Vulnerability in WooCommerce Multi Currency Plugin for WordPress
CVE-2021-4376
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2021-4376?
The WooCommerce Multi Currency plugin for WordPress is susceptible to a Missing Authorization issue. This vulnerability affects versions up to and including 2.1.17, allowing authenticated attackers to manipulate product pricing to arbitrary values. Potential exploitation could lead to unauthorized alterations, thereby impacting the integrity of e-commerce transactions and user trust.
Affected Version(s)
CURCY β Multi Currency for WooCommerce β The best free currency exchange plugin β Run smoothly on WooCommerce 7.x * <= 2.1.17