Description
Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce currency-switcher-for-woocommerce allows Stored XSS.This issue affects Currency Switcher for WooCommerce: from n/a through <= 0.0.7.
Published: 2025-03-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Currency Switcher for WooCommerce plugin contains a CSRF vulnerability that allows an attacker to inject malicious scripts that are stored in the database. When the vulnerable settings page is accessed with a forged request, the attacker can embed JavaScript that will execute in the context of any user who subsequently views the affected page. This stored XSS is possible because the plugin does not verify the authenticity of the request before saving data, linking the flaw to CWE‑352. Without additional defenses, the injected code can steal credentials, deface the site, or redirect users to phishing domains.

Affected Systems

PressMaximum Currency Switcher for WooCommerce plugin, versions up to 0.0.7.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of the flaw. The EPSS score of <1% suggests that current exploitation activity is low, and the vulnerability is not listed in the CISA KEV catalog. However, the nature of the attack—cross‑site request forgery leading to stored XSS—means that a malicious actor could exploit it by tricking an authenticated user into visiting a crafted URL or by embedding the exploit in an external resource. The lack of a required user interaction beyond activating a form submission increases the likelihood that the flaw could be abused in compromised or shared administrative accounts.

Generated by OpenCVE AI on May 1, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to the latest release (≥0.0.8) to remove the flaw
  • If the plugin is not essential, remove or disable it entirely
  • Review the plugin’s code or settings pages to ensure that all input is properly sanitized and that a valid CSRF token is required before any modification is accepted
  • Deploy a web application firewall rule to block suspicious script payloads in plugin configuration submissions

Generated by OpenCVE AI on May 1, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8344 Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce allows Stored XSS. This issue affects Currency Switcher for WooCommerce: from n/a through 0.0.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce allows Stored XSS. This issue affects Currency Switcher for WooCommerce: from n/a through 0.0.7. Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce currency-switcher-for-woocommerce allows Stored XSS.This issue affects Currency Switcher for WooCommerce: from n/a through <= 0.0.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce allows Stored XSS. This issue affects Currency Switcher for WooCommerce: from n/a through 0.0.7.
Title WordPress Currency Switcher for WooCommerce plugin <= 0.0.7 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.898Z

Reserved: 2025-03-26T09:21:01.288Z

Link: CVE-2025-30857

cve-icon Vulnrichment

Updated: 2025-03-27T13:58:15.067Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:46.700

Modified: 2026-04-23T15:27:12.230

Link: CVE-2025-30857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses