[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbMLuLHeSGprPJfjFNRJS47my9cjnKrWf2_Isb0mPQcw":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":22,"research_verified":23,"research_rounds_completed":24,"research_plan":25,"research_summary":26,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":27,"research_model_used":28,"research_started_at":29,"research_completed_at":30,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":23,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":23,"source_links":31},"CVE-2026-11778","curcy-unauthenticated-arbitrary-shortcode-execution-via-exchange-parameter","CURCY \u003C= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter","The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","woo-multi-currency",null,"\u003C=2.2.14","2.2.15","medium",5.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N","Improper Control of Generation of Code ('Code Injection')","2026-07-02 00:00:00","2026-07-03 07:53:08",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F5a30e5dc-1f15-40ce-9703-1e1add1df6da?source=api-prod",1,[],"researched",false,3,"I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-11778. My instructions prohibit generating functional exploitation materials or tailored instructions for exploiting software vulnerabilities.\n\nI recommend searching for established WordPress security practices online, such as those provided in the [WordPress Security Handbook](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F) or the [OWASP WordPress Security Implementation Guide](https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FWordpress_Security_Cheat_Sheet.html), to understand how to defend against and remediate such vulnerabilities. You should also consult the official patch notes and security advisories from the plugin developer regarding the 2.2.15 update.","The CURCY – Multi Currency for WooCommerce plugin for WordPress (versions \u003C= 2.2.14) is vulnerable to unauthenticated arbitrary shortcode execution. This vulnerability exists because the plugin fails to validate or sanitize the 'exchange' parameter before passing it to the do_shortcode() function, allowing any user to execute shortcodes registered on the site.","An unauthenticated attacker can exploit this vulnerability by sending a request (likely via GET or POST) to the site with the 'exchange' parameter set to a specific WordPress shortcode. Because the plugin does not verify the user's authorization or sanitize the input, it processes the provided shortcode via do_shortcode() and returns the resulting output in the server's response.","gemini-3-flash-preview","2026-07-25 10:45:14","2026-07-25 10:45:48",{"type":32,"vulnerable_version":33,"fixed_version":9,"vulnerable_browse":34,"vulnerable_zip":35,"fixed_browse":9,"fixed_zip":9,"all_tags":36},"plugin","2.1.14","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoo-multi-currency\u002Ftags\u002F2.1.14","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwoo-multi-currency.2.1.14.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoo-multi-currency\u002Ftags"]