Doofinder for WooCommerce <= 2.10.13 - Unauthenticated Information Exposure
low
The DOOFINDER Search and Discovery for WP & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.10.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 3.7
- Affected:
- up to 2.10.13
- Fixed in:
- 2.10.14
- Disclosed:
- Mar 13, 2026
CVE-2026-39542 on NVD →
DOOFINDER Search and Discovery for WP & WooCommerce [doofinder-for-woocommerce] < 2.1.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder for WooCommerce allows Stored XSS.This issue affects Doofinder for WooCommerce: from n/a through 2.1.8.
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Mar 15, 2024
CVE-2024-25596 on NVD →
Doofinder for WooCommerce <= 2.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Doofinder WP & WooCommerce Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...
- CVSS:
- 4.4
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 12, 2024
CVE-2024-25596 on NVD →
Doofinder for WooCommerce < 2.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 12, 2024
CVE-2024-25596 on NVD →
DOOFINDER Search and Discovery for WP & WooCommerce [doofinder-for-woocommerce] < 2.1.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Jan 5, 2024
CVE-2023-51678 on NVD →
Doofinder for WooCommerce <= 2.0.33 - Missing Authorization via multiple AJAX actions
medium
The Doofinder for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'doofinder_reset_credentials' and 'doofinder_force_update_on_save' anonymous AJAX functions in versions up to, and including, 2.0.33. This makes it possible for...
- CVSS:
- 5.4
- Affected:
- up to 2.0.33
- Fixed in:
- 2.1.1
- Disclosed:
- Dec 27, 2023
CVE-2023-51678 on NVD →
Doofinder for WooCommerce < 2.1.1 - Missing Authorization via multiple AJAX actions
medium
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Dec 27, 2023
CVE-2023-51678 on NVD →
DOOFINDER Search and Discovery for WP & WooCommerce [doofinder-for-woocommerce] < 2.0.0
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 1.5.49.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Dec 19, 2023
CVE-2023-40602 on NVD →
DOOFINDER Search and Discovery for WP & WooCommerce [doofinder-for-woocommerce] < 2.1.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder WP & WooCommerce Search allows Reflected XSS.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.1.7.
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
- Disclosed:
- Dec 15, 2023
CVE-2023-49185 on NVD →
Doofinder for WooCommerce <= 2.1.7 - Reflected Cross-Site Scripting via tab
medium
The Doofinder for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting the 'tab' parameter in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.8
- Disclosed:
- Nov 29, 2023
CVE-2023-49185 on NVD →
Doofinder for WooCommerce < 2.1.8 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
- Disclosed:
- Nov 29, 2023
CVE-2023-49185 on NVD →
Doofinder for WooCommerce <= 1.5.49 - Unauthenticated Open Redirect
medium
The Doofinder for WooCommerce plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.49. This is due to insufficient validation on the redirect url supplied via an unknown parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites...
- CVSS:
- 5.4
- Affected:
- up to 1.5.49
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 17, 2023
CVE-2023-40602 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database