VYPR

Currency Switcher

by WordPress

Source repositories

CVEs (4)

  • CVE-2025-2169HigMar 11, 2025
    risk 0.48cvss 7.3epss 0.01

    The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2026-42733HigMay 27, 2026
    risk 0.46cvss 7.1epss

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1.

  • CVE-2024-38700MedJul 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injection.This issue affects WPCS: from n/a through 1.2.0.3.

  • CVE-2023-2557MedJun 9, 2023
    risk 0.21cvss 4.3epss 0.00

    The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with…