Impact
The CURCY – Multi Currency for WooCommerce – Smoothly plugin for WordPress allows untrusted input to reach WordPress’s do_shortcode function without proper validation, making this a CWE‑94 vulnerability. Consequently, attackers can inject arbitrary shortcodes that are executed with the site’s privileges, enabling remote code execution or other malicious actions.
Affected Systems
Villatheme’s CURCY Smoothly plugin deployed on WooCommerce 9.x environments for all released versions up to and including 2.2.14 is affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating moderate severity. Because the attack requires no authentication and can be triggered by any network user able to craft an HTTP request carrying a malicious 'exchange' parameter, the practical exploitation risk is relatively straightforward. However, the EPSS score of less than 1% indicates that, at present, there is a very low probability that this flaw is actively exploited in the wild. The fact that the flaw is not listed in the CISA KEV catalog further suggests that no known exploit has been documented. Consequently, while the possibility of arbitrary shortcode execution exists, the likelihood of an attacker successfully using this flaw remains low, but the potential impact remains significant due to the remote code execution capability inherent in the use of do_shortcode.
OpenCVE Enrichment