Plugin Vulnerability Hub
Plugin 16 known issues Latest disclosed May 14, 2026

FOX – Currency Switcher Professional for WooCommerce Vulnerabilities

Review known vulnerability records for the WordPress plugin FOX – Currency Switcher Professional for WooCommerce (`woocommerce-currency-switcher`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-4094, CVE-2026-39501 and CVE-2026-39497, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
16
High or Critical
4
Patch Coverage
100%
Last Updated
May 14, 2026
Related Security Guides

Use these guides while reviewing FOX – Currency Switcher Professional for WooCommerce fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize FOX – Currency Switcher Professional for WooCommerce remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
15
1. Match the Package
Confirm the installed WordPress plugin slug is woocommerce-currency-switcher before acting on any CVE from this cluster.
2. Sort by Severity
Start with 4 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
16 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into FOX – Currency Switcher Professional for WooCommerce CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
16
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2021-24566
WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 - Authenticated...
Local File Inclusion Versions up to 1.3.7 1.3.7.1 CVSS 8.8
CVE-2026-4094
FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorizatio...
Cross-Site Request Forgery Versions up to 1.4.5 1.4.6 CVSS 8.1
CVE-2024-10640
The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticate...
Vulnerability Versions up to 1.4.2.2 1.4.2.3 CVSS 7.3
CVE-2024-8271
FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Ar...
Vulnerability Versions up to 1.4.2.1 1.4.2.2 CVSS 7.3
CVE-2024-3734
FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Ar...
Vulnerability Versions up to 1.4.1.8 1.4.1.9 CVSS 6.5
CVE-2022-4431
WOOCS <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shor...
Stored Cross-Site Scripting Versions up to 1.3.9.3 1.3.9.4 CVSS 6.4
CVE-2022-4431
WOOCS <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shor...
Stored Cross-Site Scripting Versions up to 1.3.9.2 1.3.9.3 CVSS 6.4
CVE-2022-0234
WOOCS <= 1.3.7.4 - Reflected Cross-Site Scripting via AJAX action
Cross-Site Scripting Versions up to 1.3.7.4 1.3.7.5 CVSS 6.1
CVE-2021-24566 High 1.3.7.1
CVE-2021-24566 FOX – Currency Switcher Professional for WooCommerce Local File Inclusion

WOOCS – Currency Switcher for WooCommerce Professional Free <= 1.3.7 - Authenticated Local File Inclusion

CVE-2026-4094 High 1.4.6
CVE-2026-4094 FOX – Currency Switcher Professional for WooCommerce Cross-Site Request Forgery

FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion

CVE-2024-10640 High 1.4.2.3
CVE-2024-10640 FOX – Currency Switcher Professional for WooCommerce Vulnerability

The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution

CVE-2024-8271 High 1.4.2.2
CVE-2024-8271 FOX – Currency Switcher Professional for WooCommerce Vulnerability

FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution

CVE-2024-3734 Medium 1.4.1.9
CVE-2024-3734 FOX – Currency Switcher Professional for WooCommerce Vulnerability

FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution

CVE-2022-4431 Medium 1.3.9.4
CVE-2022-4431 FOX – Currency Switcher Professional for WooCommerce Stored Cross-Site Scripting

WOOCS <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

CVE-2022-4431 Medium 1.3.9.3
CVE-2022-4431 FOX – Currency Switcher Professional for WooCommerce Stored Cross-Site Scripting

WOOCS <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

CVE-2022-0234 Medium 1.3.7.5
CVE-2022-0234 FOX – Currency Switcher Professional for WooCommerce Cross-Site Scripting

WOOCS <= 1.3.7.4 - Reflected Cross-Site Scripting via AJAX action

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for FOX – Currency Switcher Professional for WooCommerce so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
16 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 4 high severity findings.
Recent CVEs
CVE-2026-4094, CVE-2026-39501 and CVE-2026-39497
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for FOX – Currency Switcher Professional for WooCommerce

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-4094
CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, wi...

Published
May 14, 2026
Patched Release
1.4.6
Affected Versions
Versions up to 1.4.5
Next Step
Update to 1.4.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-39501
CVE-2026-39501: FOX <= 1.4.5 - Missing Authorization

The FOX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Mar 27, 2026
Patched Release
1.4.6
Affected Versions
Versions up to 1.4.5
Next Step
Update to 1.4.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-39497
CVE-2026-39497: FOX <= 1.4.5 - Authenticated (Shop manager+) SQL Injection

The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with s...

Published
Mar 23, 2026
Patched Release
1.4.6
Affected Versions
Versions up to 1.4.5
Next Step
Update to 1.4.6 or newer if supported.
Plugin High Patched: Yes CVE-2024-10640
CVE-2024-10640: The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value...

Published
Nov 08, 2024
Patched Release
1.4.2.3
Affected Versions
Versions up to 1.4.2.2
Next Step
Update to 1.4.2.3 or newer if supported.
Plugin High Patched: Yes CVE-2024-8271
CVE-2024-8271: FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value...

Published
Sep 13, 2024
Patched Release
1.4.2.2
Affected Versions
Versions up to 1.4.2.1
Next Step
Update to 1.4.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43297
CVE-2024-43297: WOOCS – WooCommerce Currency Switcher <= 1.4.2 - Missing Authorization

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_woocs_admin_theme_id AJAX action in versions up to, and including, 1.4.2. This makes it possible for authenticated at...

Published
Aug 16, 2024
Patched Release
1.4.2.1
Affected Versions
Versions up to 1.4.2
Next Step
Update to 1.4.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3734
CVE-2024-3734: FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution

The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends...

Published
Apr 24, 2024
Patched Release
1.4.1.9
Affected Versions
Versions up to 1.4.1.8
Next Step
Update to 1.4.1.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30458
CVE-2024-30458: WOOCS – WooCommerce Currency Switcher <= 1.4.1.7 - Cross-Site Request Forgery

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.7. This is due to missing or incorrect nonce validation on the save_etalon() function.. This makes it possible for unauthenticated at...

Published
Mar 28, 2024
Patched Release
1.4.1.8
Affected Versions
Versions up to 1.4.1.7
Next Step
Update to 1.4.1.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6556
CVE-2023-6556: FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Published
Dec 23, 2023
Patched Release
1.4.1.7
Affected Versions
Versions up to 1.4.1.6
Next Step
Update to 1.4.1.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-49834
CVE-2023-49834: WOOCS – WooCommerce Currency Switcher <= 1.4.1.4 - Cross-Site Request Forgery via delete_profiles_data

The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.4. This is due to missing or incorrect nonce validation on the delete_profiles_data function. This makes it possible for unauthentica...

Published
Dec 05, 2023
Patched Release
1.4.1.5
Affected Versions
Versions up to 1.4.1.4
Next Step
Update to 1.4.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-4431
CVE-2022-4431: WOOCS <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions a...

Published
Dec 20, 2022
Patched Release
1.3.9.4
Affected Versions
Versions up to 1.3.9.3
Next Step
Update to 1.3.9.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-4431
CVE-2022-4431: WOOCS <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions a...

Published
Dec 20, 2022
Patched Release
1.3.9.3
Affected Versions
Versions up to 1.3.9.2
Next Step
Update to 1.3.9.3 or newer if supported.