AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-18668

MEDIUM · CVSS 6.5 EPSS 1.81%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-11-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-18668
Severity
MEDIUM
CVSS
6.5
EPSS
1.81%

Original NVD Description

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.