CVE-2024-13487

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 6, 2025
Updated: Feb 18, 2025
CWE ID 94

Summary

CVE-2024-13487 is a vulnerability affecting the CURCY – Multi Currency plugin for WooCommerce on WordPress. Versions up to and including 2.2.5 are impacted. The issue stems from the get_products_price() function, which fails to adequately validate user input prior to executing do_shortcode. Consequently, unauthenticated assailants can exploit this flaw to inject and execute arbitrary shortcodes, potentially leading to serious security consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share