CVE-2019-18668
Currency Switcher <= 2.11.1 - Authorization Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.
Se detectó un problema en el addon Currency Switcher anteriores a 2.11.2 para WooCommerce, si un usuario suministra una moneda que no fue agregada por el administrador. En este caso, aunque la moneda no exista, será seleccionada, pero el monto del precio regresará a la moneda predeterminada. Esto significa que si un atacante suministra una moneda que no existe y vale menos que este valor predeterminado, el atacante puede comprar un artículo a un precio significativamente más barato.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-02 CVE Reserved
- 2019-11-02 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-755: Improper Handling of Exceptional Conditions
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wpvulndb.com/vulnerabilities/9936 | Third Party Advisory | |
https://www.infigo.hr/en/critical-vulnerability-in-currency-switcher-for-woocommerce-n61 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wordpress.org/plugins/currency-switcher-woocommerce/#developers | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpwham Search vendor "Wpwham" | Currency Switcher For Woocommerce Search vendor "Wpwham" for product "Currency Switcher For Woocommerce" | < 2.11.2 Search vendor "Wpwham" for product "Currency Switcher For Woocommerce" and version " < 2.11.2" | wordpress |
Affected
|