Currency Switcher <= 2.11.1 - Authorization Bypass

Missing Authorization
CVE CVE-2019-18668
CVSS Medium (6.5)
Publicly Published November 2, 2019
Last Updated January 22, 2024
Researcher Luka Sikic
Description

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

References

1 affected software package

Software Type Plugin
Software Slug currency-switcher-woocommerce (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.11.2
Patched Version
  • 2.11.2
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.