CVE-2025-47563: WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability
Missing Authorization vulnerability in villatheme CURCY allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CURCY: from n/a through 2.3.7.
Other sources
Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CURCY: from n/a through <= 2.3.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47563?
CVE-2025-47563 is considered a critical vulnerability due to missing authorization in the CURCY plugin, allowing unauthorized access to functionalities.
How do I fix CVE-2025-47563?
To fix CVE-2025-47563, users should update the CURCY plugin to the latest version beyond 2.3.7 to ensure appropriate access controls are applied.
Who is affected by CVE-2025-47563?
CVE-2025-47563 affects all users of the CURCY plugin up to and including version 2.3.7 on both VillaTheme and WordPress platforms.
What kind of vulnerability is CVE-2025-47563?
CVE-2025-47563 is a Missing Authorization vulnerability that compromises access control measures within the CURCY plugin.
What functionalities are impacted by CVE-2025-47563?
CVE-2025-47563 allows access to functionalities that are not properly constrained by Access Control Lists (ACLs), potentially leading to unauthorized actions.