PT-2026-44181 · Realmag777+1 · Fox – Currency Switcher Professional For Woocommerce+1

·

CVE-2026-9241

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FOX – Currency Switcher Professional for WooCommerce versions prior to 1.4.7
Description An authorization bypass exists when the fixed user-role pricing feature is enabled and at least one product has a privileged-role price configured. The get value() function in classes/fixed/fixed user role.php trusts the $ REQUEST['wooc order user roles'] parameter without validation to determine the user's role context for price resolution. This allows the parameter to override the legitimate role data from the $user->roles session object. Consequently, authenticated users with Subscriber-level access or higher can impersonate privileged roles, such as administrators or wholesale customers, to obtain restricted or discounted pricing.
Recommendations Update to a version newer than 1.4.6. As a temporary mitigation, disable the fixed user-role pricing feature.

Fix

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9241

Affected Products

Fox – Currency Switcher Professional For Woocommerce
Currency Switcher For Woocommerce