Reflected Cross-Site Scripting Vulnerability in Currency Switcher for WooCommerce by WordPress
CVE-2024-9217
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 March 2025
What is CVE-2024-9217?
The Currency Switcher for WooCommerce plugin for WordPress exhibits a critical security vulnerability due to improper handling of user inputs with the add_query_arg function. This flaw allows unauthenticated attackers to exploit the plugin by injecting malicious scripts that execute in the context of the user's session. By crafting a deceptive link, attackers can mislead users into triggering the execution of arbitrary scripts within their browsers, potentially compromising site integrity and user data.
Affected Version(s)
Currency Switcher for WooCommerce * <= 2.16.2