Unauthenticated Arbitrary Shortcode Execution Vulnerability in Currency Switcher Professional for WooCommerce plugin
CVE-2024-8271
7.3HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 14 September 2024
What is CVE-2024-8271?
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress has a vulnerability that allows unauthenticated users to execute arbitrary shortcodes. This issue arises because the 'woocs_get_custom_price_html' function does not adequately validate input values before processing them through the do_shortcode functionality. As a result, attackers can exploit this weakness in any version up to and including 1.4.2.1, potentially leading to unauthorized actions and security breaches.