Impact
VillaTheme CURCY, a WordPress adding multi‑currency capabilities, contains an Incorrect Calculation flaw that can be leveraged for integer attacks. The vulnerability allows an attacker to override normal bounds checks and manipulate currency conversions or settings, effectively bypassing proper authorization controls built into the plugin. This could result in unauthorized modification of financial data or application state, presenting a moderate but significant integrity risk.
Affected Systems
The affected product is the VillaTheme CURCY WordPress plugin, version 2.2.17 and any earlier releases. All installations running those versions are susceptible, irrespective of the WordPress site version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited observed exploitation activity. The likely attack vector is remote, via the web interface, where an authenticated user with privileged access could use crafted input to exercise the broken bounds checks. Exploitation requires sufficient access to the plugin’s configuration interface, but it can be leveraged by any user who can manipulate the vulnerable inputs, making the risk higher for sites with loose admin role segmentation.
OpenCVE Enrichment