First published: Tue Mar 11 2025(Updated: )
The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pluginus WordPress Currency Switcher Professional | <=1.2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2169 is considered a critical vulnerability due to the risk of arbitrary shortcode execution.
To mitigate CVE-2025-2169, update the WPCS – WordPress Currency Switcher Professional plugin to version 1.2.0.5 or later.
All versions of WPCS – WordPress Currency Switcher Professional up to and including 1.2.0.4 are affected by CVE-2025-2169.
Yes, CVE-2025-2169 can be exploited remotely by an attacker to execute arbitrary shortcodes.
While there are no publicly disclosed exploits for CVE-2025-2169 at this time, the vulnerability's nature allows for potential exploitation.