CVE-2021-24566

CVE-2021-24566: WooCommerce Currency Switcher < 1.3.7 - Authenticated (Low Privilege) Local File Inclusion

Vendor Unknown
Product FOX
Published January 16, 2024
Last update June 11, 2025

CVSS base score

What the vulnerability does

01Description

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Key dates

02Disclosure timeline

January 16, 2024 CVE published
June 11, 2025 Record updated