Project: 
Date: 
2025-September-24
Vulnerability: 
Cross Site Request Forgery
Affected versions: 
<3.5.0
CVE IDs: 
CVE-2025-10930
Description: 

This module allows you to use different currencies on your website and do currency conversion.

The module doesn't sufficiently protect routes used to enable and disable currencies from Cross-Site Request Forgery (CSRF) attacks, potentially allowing an attacker to trick an admin into changing settings.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: