CVE-2021-4379 describes an authorization bypass vulnerability in the WooCommerce Multi Currency plugin for WordPress, affecting versions up to and including 2.1.17. This flaw allows authenticated users, even those with subscriber-level permissions, to modify product prices due to a missing capability check in the wmc_bulk_fixed_price function. Rated 6.5 MEDIUM on the CVSS scale, it has a network attack vector and low attack complexity, leading to high integrity impact without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.18CPE matchmatch criteria | cpe:2.3:a:villatheme:woocommerce_multi_currency:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 2.1.17CPE match | cpe:2.3:a:villatheme:curcy_-_woocommerce_multi_currency_-_currency_switcher:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.