CVE Feed

    Dashboard / CVE / CVE-2019-18668

    CVE-2019-18668

    An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

    Published:Nov 2, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 2, 2019
    EPSS Score:0.00159
    CVSS Score:6.5

    Affected Products

    Vendor
    Wpwham
    Product
    Currency Switcher For Woocommerce

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High