Impact
An unauthenticated Cross Site Scripting vulnerability exists in the WordPress CURCY plugin (versions 2.2.16 and earlier). It allows an attacker to inject arbitrary client‑side scripts that are executed in the browser of any user who loads a crafted page or link. The injected code can steal session cookies, deface the site, perform phishing or execute additional malicious payloads. The primary impact is on the confidentiality and integrity of user credentials and the integrity of the site’s content.
Affected Systems
This vulnerability affects the CURCY – Multi Currency for WooCommerce plugin developed by VillaTheme, available for WordPress. All installations of CURCY 2.2.16 or older are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. EPSS is not available, but the lack of authentication requirements makes the attack vector easy to exploit. The vulnerability is not listed in the CISA KEV catalog, yet the potential for widespread impact remains because any visitor to the affected site could be exposed to malicious scripts.
OpenCVE Enrichment