📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Enterprise Software / ERP Systems CRITICAL 20m Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global vulnerability Enterprise Software HIGH 6h Global general Cybersecurity Operations HIGH 6h Global general Cybersecurity Industry LOW 6h Global supply_chain Multiple Sectors CRITICAL 6h Global vulnerability Enterprise Software / ERP Systems CRITICAL 20m Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global vulnerability Enterprise Software HIGH 6h Global general Cybersecurity Operations HIGH 6h Global general Cybersecurity Industry LOW 6h Global supply_chain Multiple Sectors CRITICAL 6h Global vulnerability Enterprise Software / ERP Systems CRITICAL 20m Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global vulnerability Enterprise Software HIGH 6h Global general Cybersecurity Operations HIGH 6h Global general Cybersecurity Industry LOW 6h Global supply_chain Multiple Sectors CRITICAL 6h
Vulnerabilities

CVE-2026-4094

High
CWE-862 — Weakness Type
Published: May 15, 2026  ·  Modified: May 22, 2026  ·  Source: NVD
CVSS v3
8.1
🔗 NVD Official
📄 Description (English)

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if the site is configured to allow Subscriber access to 'wp-admin' pages.

🤖 AI Executive Summary

CVE-2026-4094 affects the FOX Currency Switcher Professional WooCommerce plugin (versions ≤1.4.5), allowing authenticated attackers with Contributor-level access to delete entire multi-currency configurations via a missing capability check and absent nonce verification. The vulnerability is exploitable via CSRF against administrators and potentially Subscribers with wp-admin access, causing complete loss of currency configuration data. With no patch currently available and high CVSS score of 8.1, immediate mitigation is critical for e-commerce platforms in Saudi Arabia.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 20, 2026 03:24
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi e-commerce businesses, particularly those using WooCommerce for multi-currency operations serving GCC markets. High-risk sectors include: (1) Retail/E-commerce platforms handling SAR and regional currencies; (2) Banking sector fintech solutions offering multi-currency payment gateways; (3) ARAMCO and energy sector procurement platforms with international transactions; (4) Telecom companies (STC, Mobily) with online services; (5) Government e-services platforms if using WooCommerce. The CSRF exploitation vector is particularly dangerous as it requires no user interaction beyond visiting a malicious link, making it suitable for targeted attacks against Saudi business decision-makers.
🏢 Affected Saudi Sectors
E-commerce/Retail Banking and Financial Services Energy (ARAMCO and subsidiaries) Telecommunications (STC, Mobily, Zain) Government and Public Services Healthcare Hospitality and Tourism Import/Export and Logistics
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Disable the FOX Currency Switcher Professional plugin immediately until patch is available
2. If disabling is not feasible, restrict wp-admin access to trusted IP ranges only via .htaccess or WAF rules
3. Implement strict user role management - audit and remove unnecessary Contributor/Subscriber wp-admin access
4. Review WordPress user accounts and remove any suspicious or unused accounts with elevated privileges

COMPENSATING CONTROLS:
1. Deploy Web Application Firewall (WAF) rules to block requests containing 'woocs_reset' parameter
2. Implement CSRF token validation at application level if possible through custom code
3. Enable WordPress security plugins (Wordfence, Sucuri) with CSRF protection and request filtering
4. Configure Content Security Policy (CSP) headers to prevent unauthorized script execution
5. Implement request logging and alerting for any wp-admin access with suspicious parameters

DETECTION RULES:
1. Monitor WordPress access logs for requests containing 'woocs_reset' parameter
2. Alert on any wp-admin page access from Contributor-level or below accounts
3. Track database changes to wp_options table for currency configuration deletions
4. Monitor for unusual referrer headers in wp-admin requests (CSRF indicator)
5. Log all user role changes and capability modifications

PATCHING GUIDANCE:
1. Contact plugin vendor for security update timeline
2. Prepare rollback plan and database backups before applying any updates
3. Test patches in staging environment before production deployment
4. Document all currency configurations before plugin update as contingency
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تعطيل إضافة FOX Currency Switcher Professional فوراً حتى توفر التصحيح
2. إذا لم يكن التعطيل ممكناً، قيد وصول wp-admin إلى نطاقات IP موثوقة فقط عبر .htaccess أو قواعد WAF
3. تنفيذ إدارة صارمة لأدوار المستخدمين - تدقيق وإزالة وصول wp-admin غير الضروري للمساهمين/المشتركين
4. مراجعة حسابات مستخدمي WordPress وإزالة أي حسابات مريبة أو غير مستخدمة بامتيازات مرتفعة

الضوابط التعويضية:
1. نشر قواعد جدار الحماية (WAF) لحجب الطلبات التي تحتوي على معامل 'woocs_reset'
2. تنفيذ التحقق من رمز CSRF على مستوى التطبيق إن أمكن من خلال كود مخصص
3. تفعيل إضافات أمان WordPress (Wordfence, Sucuri) مع حماية CSRF وتصفية الطلبات
4. تكوين رؤوس Content Security Policy (CSP) لمنع تنفيذ البرامج النصية غير المصرح بها
5. تنفيذ تسجيل الطلبات والتنبيهات لأي وصول wp-admin بمعاملات مريبة

قواعد الكشف:
1. مراقبة سجلات وصول WordPress للطلبات التي تحتوي على معامل 'woocs_reset'
2. التنبيه على أي وصول صفحة wp-admin من حسابات بمستوى المساهم أو أقل
3. تتبع تغييرات قاعدة البيانات في جدول wp_options لحذف إعدادات العملة
4. مراقبة رؤوس المحيل غير العادية في طلبات wp-admin (مؤشر CSRF)
5. تسجيل جميع تغييرات أدوار المستخدمين وتعديلات القدرات

إرشادات التصحيح:
1. اتصل بمورد الإضافة للحصول على جدول زمني لتحديث الأمان
2. تحضير خطة التراجع والنسخ الاحتياطية لقاعدة البيانات قبل تطبيق أي تحديثات
3. اختبر التصحيحات في بيئة التطوير قبل نشر الإنتاج
4. وثق جميع إعدادات العملة قبل تحديث الإضافة كخطة طوارئ
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 - Access Control and Authentication 5.2.1 - User Access Management 5.3.1 - Privileged Access Management 6.1.1 - Data Protection and Privacy 6.2.1 - Data Integrity and Availability 7.1.1 - Security Event Logging and Monitoring
🔵 SAMA CSF
Governance & Risk Management - Access Control Policies Information Security - Data Protection and Integrity Operational Resilience - Incident Detection and Response Third-Party Risk Management - Vendor Security Assessment
🟡 ISO 27001:2022
A.5.1 - Policies for information security A.6.1 - Internal organization A.8.1 - Asset management A.9.1 - Access control A.9.2 - User access management A.9.4 - Access control to information and other associated assets A.12.4 - Logging A.14.2 - Development security
🟣 PCI DSS v4.0.1
Requirement 1.1 - Firewall configuration standards Requirement 2.1 - Default security parameters Requirement 6.2 - Security patches and updates Requirement 7.1 - Access control implementation Requirement 8.1 - User identification and authentication Requirement 10.2 - User access logging
📊 CVSS Score
8.1
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.1
CWECWE-862
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-05-15
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-862
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.