Impact
The vulnerability in WBW Currency Switcher for WooCommerce allows an attacker to bypass authorization checks and modify currency switcher settings without proper privileges. This could lead to incorrect pricing, compromised transaction integrity, and potential financial loss. The weakness is identified as CWE‑862: Missing Authorization.
Affected Systems
WBW Plugins’ WBW Currency Switcher for WooCommerce plugin is affected whenever the installed version is 2.2.5 or earlier. Administrators should verify the current version on their WordPress sites.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests low predicted exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need access to the WordPress backend or a vulnerability that allows unauthenticated configuration changes; this is inferred from the description of incorrectly configured access control levels.
OpenCVE Enrichment