CVE-2026-97071: WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CURCY pluginto a version that resolves this vulnerability.Fixed in 2.2.18
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The listed CVSS vector indicates that exploitation is network-accessible and requires neither authentication nor user interaction. An unauthenticated remote attacker could potentially target an affected CURCY installation.
What is the impact if exploitation succeeds?
The vulnerability is rated medium severity with a 5.3 CVSS score. The stated impact is limited to integrity; no confidentiality or availability impact is listed.
Which versions are affected?
CURCY woo-multi-currency versions through 2.2.17 are affected. The provided information does not identify a fixed version.