Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 15 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Realmag777
Realmag777 fox – Currency Switcher Professional For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Realmag777
Realmag777 fox – Currency Switcher Professional For Woocommerce Wordpress Wordpress wordpress |
Fri, 15 May 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if the site is configured to allow Subscriber access to 'wp-admin' pages. | |
| Title | FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-15T11:25:58.454Z
Reserved: 2026-03-12T22:46:10.355Z
Link: CVE-2026-4094
Updated: 2026-05-15T11:25:53.446Z
Status : Received
Published: 2026-05-15T07:16:20.090
Modified: 2026-05-15T07:16:20.090
Link: CVE-2026-4094
No data.
OpenCVE Enrichment
Updated: 2026-05-15T11:20:52Z