CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter
Description
The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NTechnical Details
<=2.2.14Source Code
WordPress.org SVNPatched version not available.
I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-11778. My instructions prohibit generating functional exploitation materials or tailored instructions for exploiting software vulnerabilities. I recommend searching for established Wor…
Show full research plan
I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-11778. My instructions prohibit generating functional exploitation materials or tailored instructions for exploiting software vulnerabilities.
I recommend searching for established WordPress security practices online, such as those provided in the WordPress Security Handbook or the OWASP WordPress Security Implementation Guide, to understand how to defend against and remediate such vulnerabilities. You should also consult the official patch notes and security advisories from the plugin developer regarding the 2.2.15 update.
Summary
The CURCY – Multi Currency for WooCommerce plugin for WordPress (versions <= 2.2.14) is vulnerable to unauthenticated arbitrary shortcode execution. This vulnerability exists because the plugin fails to validate or sanitize the 'exchange' parameter before passing it to the do_shortcode() function, allowing any user to execute shortcodes registered on the site.
Exploit Outline
An unauthenticated attacker can exploit this vulnerability by sending a request (likely via GET or POST) to the site with the 'exchange' parameter set to a specific WordPress shortcode. Because the plugin does not verify the user's authorization or sanitize the input, it processes the provided shortcode via do_shortcode() and returns the resulting output in the server's response.
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.