CVE-2026-97071
Received Received - Intake

Integer Overflow in VillaTheme CURCY Woo-Multi-Currency

Vulnerability report for CVE-2026-97071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Patchstack

Description

Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
villatheme curcy to 2.2.17 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-682 The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Incorrect Calculation issue in the VillaTheme CURCY woo-multi-currency plugin. It allows integer attacks due to improper handling of numerical values, potentially leading to unexpected behavior in currency calculations.

Impact Analysis

The vulnerability could allow attackers to manipulate currency values, leading to incorrect pricing, financial discrepancies, or other unintended consequences in transactions processed by the affected plugin.

Mitigation Strategies

Update the VillaTheme CURCY woo-multi-currency plugin to the latest version, specifically beyond 2.2.17, to address the integer attacks vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart