CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'adminhead' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the woocsreset parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if the site is configured to allow Subscriber access to 'wp-admin' pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4094?
The severity of CVE-2026-4094 is classified as medium due to its potential for unauthorized data loss.
How do I fix CVE-2026-4094?
To fix CVE-2026-4094, update the FOX Currency Switcher Professional for WooCommerce plugin to version 1.4.6 or later.
What kind of vulnerability is CVE-2026-4094?
CVE-2026-4094 is a missing authorization vulnerability that allows authenticated users to delete configurations.
Who is affected by CVE-2026-4094?
Users of the FOX Currency Switcher Professional for WooCommerce plugin version 1.4.5 and below are affected by CVE-2026-4094.
Can CVE-2026-4094 lead to data breaches?
Yes, CVE-2026-4094 can lead to unauthorized data loss, which may result in potential data breaches.