
Exchange Rates Widget Security & Risk Analysis
wordpress.org/plugins/exchange-rates-widget❤️ Is a magic and easy-to-use with beautiful UI widget. Included 190+ world currencies with popular cryptocurrencies.
Is Exchange Rates Widget Safe to Use in 2026?
Generally Safe
Score 100/100Exchange Rates Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The exchange-rates-widget plugin version 1.4.1 exhibits a mixed security posture. On the positive side, the static analysis indicates good practices regarding SQL queries, which are exclusively handled by prepared statements, and a high percentage of output escaping. The absence of external HTTP requests and the limited attack surface also contribute to a generally favorable assessment. However, several concerns warrant attention. The plugin has a history of a medium severity Cross-Site Scripting (XSS) vulnerability, with the last recorded incident being quite recent (March 2024). While currently unpatched CVEs are zero, this history suggests potential for future undiscovered or re-emerging vulnerabilities, especially if input validation or output escaping practices degrade. A critical weakness is the complete lack of capability checks and nonce checks on its single entry point (a shortcode). This means any authenticated user, regardless of their role, could potentially trigger the shortcode's functionality, opening the door to privilege escalation or unintended actions if the shortcode's logic is not robustly secured against malicious input. The taint analysis shows no flows, which is good, but the lack of thorough checks on the shortcode's entry point is a significant oversight.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- History of medium severity XSS vulnerability
- Moderate percentage of unescaped output
Exchange Rates Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Exchange Rates Widget <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Exchange Rates Widget Code Analysis
Output Escaping
Exchange Rates Widget Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Exchange Rates Widget Maintenance & Trust
Maintenance Signals
Community Trust
Exchange Rates Widget Alternatives
Money92 Forex Widgets
money92-forex-widgets
Two WordPress shortcodes that display Forex rates in PKR and a currency conversion calculator.
Currency Converter Widget
currency-converter-widget
Free, fast, and beautiful currency converter widget with 170+ currencies, live exchange rates, and 11 widget styles.
Exchange Rates
exchange-rates
Currency Converter & Exchange Rates Widgets, easy-to-use, with beautiful UI. 🔑 No API key needed, ❤️ plug and play.
Exchange Rate Table
exchange-rate-table
Display an exchange rate table for any currency in the world. Select from a choice of table sizes and formats.
FX Live Prices
fx-live-prices
FX Live Prices WordPress Plugin provides live forex rates and indicators and cross-exchange rates. Prices quote update frequency is 1-5 seconds.
Exchange Rates Widget Developer Profile
9 plugins · 5K total installs
How We Detect Exchange Rates Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exchange-rates-widget/css/erw.css/wp-content/plugins/exchange-rates-widget/js/erw.js/wp-content/plugins/exchange-rates-widget/admin/css/erw-admin.css/wp-content/plugins/exchange-rates-widget/js/erw.jsexchange-rates-widget/css/erw.css?ver=exchange-rates-widget/js/erw.js?ver=HTML / DOM Fingerprints
erw_widget<!-- START: Exchange Rates Widget --><!-- END: Exchange Rates Widget -->data-erw-shortcodeerw_ajax_object<iframe src="https://currencyrate.today/exchange.php?