Description
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Update plugin
AI Analysis

Impact

VillaTheme CURCY, a WordPress adding multi‑currency capabilities, contains an Incorrect Calculation flaw that can be leveraged for integer attacks. The vulnerability allows an attacker to override normal bounds checks and manipulate currency conversions or settings, effectively bypassing proper authorization controls built into the plugin. This could result in unauthorized modification of financial data or application state, presenting a moderate but significant integrity risk.

Affected Systems

The affected product is the VillaTheme CURCY WordPress plugin, version 2.2.17 and any earlier releases. All installations running those versions are susceptible, irrespective of the WordPress site version.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited observed exploitation activity. The likely attack vector is remote, via the web interface, where an authenticated user with privileged access could use crafted input to exercise the broken bounds checks. Exploitation requires sufficient access to the plugin’s configuration interface, but it can be leveraged by any user who can manipulate the vulnerable inputs, making the risk higher for sites with loose admin role segmentation.

Generated by OpenCVE AI on October 5, 2026 at 10:40 UTC.

Remediation

Vendor Solution

Update the WordPress CURCY plugin to the latest available version (at least 2.2.18).


OpenCVE Recommended Actions

  • Install the latest CURCY plugin version 2.2.18 or newer to remove the broken calculation logic
  • Restrict access to the CURCY configuration pages to administrators or users with explicitly granted rights
  • Audit site logs for unexpected currency change actions and review all active plugins for excess permissions

Generated by OpenCVE AI on October 5, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
Title WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability
Weaknesses CWE-682
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:40:24.198Z

Reserved: 2026-09-24T00:20:10.982Z

Link: CVE-2026-97071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:13.887

Modified: 2026-10-05T09:17:13.887

Link: CVE-2026-97071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses