CVE-2023-2556 MEDIUM

CVE-2023-2556: WPCS – WordPress Currency Switcher Professional <= 1.1.9 - Missing Authorization to Arbitrary Custom Drop-Down Currency Switcher Deletion

Vendor Realmag777
Product WPCS – WordPress Currency Switcher Professional
Weakness CWE-862 · Missing authorization
Published June 9, 2023
Last update April 8, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete an arbitrary custom drop-down currency switcher.

Explanation of Vulnerability in Simple Terms

02Summary

The WPCS – WordPress Currency Switcher Professional plugin through version 1.1.9 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify plugin settings or data without proper permission validation. This allows unauthorized changes to currency switching behavior or configuration that should be restricted to administrators.

What an attacker can do

03Attacker Capabilities

Modify plugin settings or data without admin permission.

Potential impact on your site

04Site Impact

Unauthorized users can alter currency switcher configuration, potentially disrupting store functionality or customer experience.

Conditions required to exploit

05Prerequisites

Attacker must be logged in as a low-privilege user (subscriber or contributor).

Key dates

06Disclosure timeline

June 9, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE