SQL Injection Vulnerability in WooCommerce Multi Currency Plugin for WordPress
CVE-2024-13320

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 March 2025

Summary

The WooCommerce Multi Currency - Currency Switcher plugin for WordPress is exposed to SQL Injection due to inadequate escaping of the 'wc_filter_price_meta[where]' parameter. This vulnerability allows unauthenticated attackers to manipulate existing SQL queries to extract sensitive data from the database, impacting the overall security of websites utilizing this plugin. Users are advised to upgrade to the latest version to mitigate risks.

Affected Version(s)

CURCY - WooCommerce Multi Currency - Currency Switcher * <= 2.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc)
.