Description
WordPress Plugin WooCommerce Multi Currency-Currency Switcher is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the price of all products. WordPress Plugin WooCommerce Multi Currency-Currency Switcher version 2.1.17 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.1.18 or latest
References
Related Vulnerabilities
WordPress Plugin Subscribe To Comments Reloaded Cross-Site Scripting (150611)
WordPress Plugin Contact Form 7 Multi-Step Forms Security Bypass (3.0.8)
MyBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-5131)
WordPress Plugin Network Publisher 'networkpub_key' Parameter Cross-Site Scripting (5.0.1)