CVE-2026-9241: FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the getvalue() function in classes/fixed/fixeduserrole.php trusting the attacker-controlled $REQUEST['woocorderuserroles'] parameter to determine the user's role context for role-based price resolution without any validation, allowing it to override the legitimate role data derived from the authenticated user's session object via $user->roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate higher-privileged roles — such as wholesale customer or administrator — and obtain discounted or otherwise restricted pricing that should not be available to their actual role. This vulnerability only has practical impact when the fixed user-role pricing feature is enabled and at least one product has a privileged-role price configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FOX – Currency Switcher Professional for WooCommerceto a version that resolves this vulnerability.Fixed in 1.4.6 - Configuration
Disable the “fixed user-role pricing” feature in the FOX – Currency Switcher Professional for WooCommerce plugin, since the Authorization Bypass has practical impact only when this feature is enabled and at least one product has a privileged-role price configured.
FOX – Currency Switcher Professional for WooCommerce (WordPress plugin) fixed user-role pricing feature = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9241?
CVE-2026-9241 has a medium severity rating of 4.3.
What vulnerability does CVE-2026-9241 describe?
CVE-2026-9241 describes an authenticated authorization bypass vulnerability in the FOX Currency Switcher Professional for WooCommerce plugin.
How do I fix CVE-2026-9241?
To fix CVE-2026-9241, update the FOX Currency Switcher Professional for WooCommerce plugin to version 1.4.7 or later.
What can attackers achieve with CVE-2026-9241?
Attackers can exploit CVE-2026-9241 to gain unauthorized access to user roles via the 'wooc_order_user_roles' parameter.
Which versions of the FOX Currency Switcher Professional for WooCommerce are affected by CVE-2026-9241?
All versions of the FOX Currency Switcher Professional for WooCommerce up to and including 1.4.6 are affected by CVE-2026-9241.