plugin

Doofinder For Woocommerce Vulnerabilities

12 known security issues reported for the Doofinder For Woocommerce WordPress plugin. Most recent disclosed Mar 13, 2026.

7 medium 1 low

Running Doofinder For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Doofinder for WooCommerce <= 2.10.13 - Unauthenticated Information Exposure

low

The DOOFINDER Search and Discovery for WP & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.10.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
3.7
Affected:
up to 2.10.13
Fixed in:
2.10.14
Disclosed:
Mar 13, 2026

CVE-2026-39542 on NVD →

DOOFINDER Search and Discovery for WP &amp; WooCommerce [doofinder-for-woocommerce] < 2.1.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder for WooCommerce allows Stored XSS.This issue affects Doofinder for WooCommerce: from n/a through 2.1.8.

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Mar 15, 2024

CVE-2024-25596 on NVD →

Doofinder for WooCommerce <= 2.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium

The Doofinder WP & WooCommerce Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...

CVSS:
4.4
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
Feb 12, 2024

CVE-2024-25596 on NVD →

Doofinder for WooCommerce < 2.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium
Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Feb 12, 2024

CVE-2024-25596 on NVD →

DOOFINDER Search and Discovery for WP &amp; WooCommerce [doofinder-for-woocommerce] < 2.1.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Jan 5, 2024

CVE-2023-51678 on NVD →

Doofinder for WooCommerce <= 2.0.33 - Missing Authorization via multiple AJAX actions

medium

The Doofinder for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'doofinder_reset_credentials' and 'doofinder_force_update_on_save' anonymous AJAX functions in versions up to, and including, 2.0.33. This makes it possible for...

CVSS:
5.4
Affected:
up to 2.0.33
Fixed in:
2.1.1
Disclosed:
Dec 27, 2023

CVE-2023-51678 on NVD →

Doofinder for WooCommerce < 2.1.1 - Missing Authorization via multiple AJAX actions

medium
Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Dec 27, 2023

CVE-2023-51678 on NVD →

DOOFINDER Search and Discovery for WP &amp; WooCommerce [doofinder-for-woocommerce] < 2.0.0

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 1.5.49.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Dec 19, 2023

CVE-2023-40602 on NVD →

DOOFINDER Search and Discovery for WP &amp; WooCommerce [doofinder-for-woocommerce] < 2.1.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder WP & WooCommerce Search allows Reflected XSS.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.1.7.

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Dec 15, 2023

CVE-2023-49185 on NVD →

Doofinder for WooCommerce <= 2.1.7 - Reflected Cross-Site Scripting via tab

medium

The Doofinder for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting the 'tab' parameter in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Nov 29, 2023

CVE-2023-49185 on NVD →

Doofinder for WooCommerce < 2.1.8 - Reflected Cross-Site Scripting

medium
Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Nov 29, 2023

CVE-2023-49185 on NVD →

Doofinder for WooCommerce <= 1.5.49 - Unauthenticated Open Redirect

medium

The Doofinder for WooCommerce plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.49. This is due to insufficient validation on the redirect url supplied via an unknown parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites...

CVSS:
5.4
Affected:
up to 1.5.49
Fixed in:
2.0.0
Disclosed:
Aug 17, 2023

CVE-2023-40602 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database