CVE-2026-39497: WordPress FOX plugin <= 1.4.5 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39497?
CVE-2026-39497 is classified as a medium severity SQL Injection vulnerability in the RealMag777 FOX WooCommerce Currency Switcher plugin.
How do I fix CVE-2026-39497?
To fix CVE-2026-39497, update the RealMag777 FOX WooCommerce Currency Switcher plugin to version 1.4.6 or later.
What impact does CVE-2026-39497 have on WordPress sites?
CVE-2026-39497 allows attackers to execute blind SQL injection attacks, potentially compromising the database.
Which versions of the FOX plugin are affected by CVE-2026-39497?
CVE-2026-39497 affects all versions of the RealMag777 FOX WooCommerce Currency Switcher plugin up to and including version 1.4.5.
Is there a workaround for CVE-2026-39497 if I cannot update immediately?
Currently, there is no publicly disclosed workaround for CVE-2026-39497 other than updating to a patched version.