Sceawere

Vulnerability Detail

CVE-2026-97071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CURCY Integer Calculation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
10h ago
Vendor
VillaTheme
Product
CURCY
Attack Type
Incorrect Calculation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T09:17:13.887Z",
  "pubdate": "2026-10-05T09:17:13.887Z",
  "executiveSummary": "The VillaTheme CURCY woo-multi-currency plugin is susceptible to an incorrect calculation vulnerability, categorized as an integer attack vector.\nThis security flaw impacts versions from n/a through 2.2.17. The vulnerability exists due to improper handling of numeric data types during currency conversion processes, potentially leading to inaccurate financial calculations.\nAn unauthenticated or authenticated attacker capable of triggering currency conversion routines can exploit this discrepancy to manipulate price calculations within the WooCommerce environment.\nThe risk implication is significant, as it may allow for the underpayment of products or services by manipulating the final cart totals through malformed input or integer overflow/underflow conditions.\nExploitation does not necessarily require administrative privileges, depending on the exposure of the currency switching mechanisms, and poses a direct threat to the integrity of e-commerce transactions managed by the plugin.",
  "technicalDetails": "The vulnerability resides within the CURCY woo-multi-currency plugin's internal engine responsible for calculating and applying exchange rates during the checkout or price display process.\nThe root cause is identified as an Incorrect Calculation vulnerability, where the application fails to perform adequate bounds checking or type validation when processing numeric values used in currency conversion.\nIn scenarios involving multi-currency switching, the plugin performs arithmetic operations to convert base currency prices to a target currency. If the input parameters—such as custom exchange rates or cart quantity variables—are not properly sanitized or cast to appropriate integer/float types, the application becomes susceptible to integer overflow or rounding logic errors.\nThe attack flow typically begins with an actor interacting with the plugin's frontend currency switcher or by injecting specifically crafted parameters into the HTTP request responsible for updating the session currency data. By supplying values that trigger an integer wrap-around or forcing the conversion logic into an undefined mathematical state, an attacker can manipulate the resulting price returned by the backend.\nBecause the CURCY plugin handles financial data, the calculation logic is highly sensitive to the precision and size of numeric inputs. A successful exploit forces the plugin to return an incorrect, often lower, price for items in the shopping cart. This persists until the session currency is reset or the calculation routine is re-executed with sanitized data.\nThe vulnerable component is the core calculation class responsible for currency conversion logic. Versions 2.2.17 and earlier fail to implement necessary arithmetic sanity checks, allowing the underlying PHP environment to perform imprecise calculations when handling large integers or specific floating-point conversions.\nThere are no explicit authentication requirements to trigger these calculations, as currency conversion is a standard feature exposed to public-facing e-commerce store visitors. The post-exploitation impact includes financial loss to the vendor due to compromised checkout totals, potentially leading to unauthorized price reduction for goods and services."
}
CVE-2026-97071: CURCY Integer Calculation Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere