
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39497 is a Blind SQL Injection vulnerability in the FOX – Currency Switcher Professional for WooCommerce WordPress plugin, developed by RealMag777. It affects all versions up to and including 1.4.5, with version 1.4.6 released as the patched fix. The vulnerability was reported by researcher timomangcut on February 21, 2026, and published by Patchstack on March 23, 2026, with CVE assignment on April 8, 2026. It carries a CVSS v3.1 base score of 7.6 (High), assessed by CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically enabling Blind SQL Injection. The flaw arises from insufficient sanitization of user-supplied input before it is incorporated into SQL queries within the plugin. Exploitation requires High privileges (Shop Manager level) and is network-accessible with low attack complexity, but the changed scope indicates the impact can extend beyond the plugin itself to the underlying database. No public proof-of-concept code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an authenticated attacker with Shop Manager privileges to perform blind SQL injection against the WordPress site's database, enabling extraction of sensitive information such as user credentials, order data, and other stored records. The CVSS scope is rated as Changed, meaning the impact can extend beyond the plugin's own data boundary to the broader database. Integrity and availability impacts are rated None and Low respectively, making data confidentiality the primary concern (Patchstack, NVD).
The vulnerability has an EPSS score of approximately 0.021% (0.000210), indicating a low probability of exploitation in the near term. There is no evidence of active in-the-wild exploitation, no known public exploit code, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite being theoretically usable in mass-exploit campaigns targeting WordPress plugins (Patchstack).
SLEEP() or conditional logic) to infer database contents character by character.SLEEP, AND 1=1, OR 1=1, UNION SELECT).SLEEP()-based blind SQL injection probing.The vendor has released version 1.4.6 of the FOX – Currency Switcher Professional for WooCommerce plugin, which resolves this vulnerability. Site administrators should update to version 1.4.6 or later immediately via the WordPress plugin dashboard. If immediate update is not possible, consider restricting Shop Manager account access or temporarily deactivating the plugin. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Patchstack, which coordinated the disclosure, classifies this as a low-priority vulnerability with limited exploitation likelihood, noting the requirement for high-level authenticated access. No significant media coverage, researcher commentary, or social media discussion has been identified beyond the initial Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."