FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution
Description
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the 'woocs_get_custom_price_html' function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated attackers can execute arbitrary WordPress shortcodes via the FOX Currency Switcher plugin up to v1.4.2.1.
Vulnerability
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress versions up to and including 1.4.2.1 contains an arbitrary shortcode execution vulnerability in the woocs_get_custom_price_html function. The plugin fails to properly validate a value before passing it to the WordPress do_shortcode function, allowing unauthenticated attackers to execute arbitrary shortcodes [1].
Exploitation
An attacker does not require authentication or any special network position beyond standard HTTP access to the WordPress instance. By crafting a specially crafted request that triggers the woocs_get_custom_price_html function with an uncontrolled shortcode input, the attacker can supply arbitrary shortcode syntax that WordPress will evaluate and execute [1].
Impact
Successful exploitation allows an unauthenticated attacker to execute any WordPress shortcode, including those provided by other plugins or themes. This can lead to data disclosure, file writes, privilege escalation, or remote code execution depending on the available shortcodes in the environment [1].
Mitigation
The vendor has released version 1.4.3 to address this vulnerability; users should update to that version or later [1]. No workaround is documented. The plugin is not listed in CISA's Known Exploited Vulnerabilities catalog as of this writing.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- realmag777/FOX – Currency Switcher Professional for WooCommercev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.