#VU22489 Input validation error in Currency Switcher for WooCommerce - CVE-2019-18668
Published: November 4, 2019
Currency Switcher for WooCommerce
Algoritmika Ltd
Description
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated attacker can provide a currency that isn't enabled in the settings and is worth less than this default and eventually purchase an item for a significantly cheaper price.