WordPress · Curcy – Multi Currency For Woocommerce · CVE-2026-11778
**Name of the Vulnerable Software and Affected Versions**
The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x versions prior to 2.2.15
**Description**
Unauthenticated attackers can execute arbitrary shortcodes because the software fails to properly validate a value before running the `do shortcode()` function. This issue occurs via the `exchange` parameter.
**Recommendations**
Update the plugin to a version later than 2.2.14.