Vulnerabilities > Pluginus > Wordpress Currency Switcher Professional

DATE CVE VULNERABILITY TITLE RISK
2023-06-09 CVE-2023-2555 Unspecified vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9.
network
low complexity
pluginus
4.3
2023-06-09 CVE-2023-2557 Missing Authorization vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9.
network
low complexity
pluginus CWE-862
4.3
2023-06-09 CVE-2023-2558 Unspecified vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
pluginus
5.4