Doofinder records
4 published records for vendor doofinder.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2023-51678No exploit | WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Controldoofinder · doofinder · CWE-352 | Medium6.5 | — | 0.2% | Jan 5, 2024 |
24Monitor | CVE-2023-40602No exploit | WordPress Doofinder for WooCommerce Plugin <= 1.5.49 is vulnerable to Open Redirectiondoofinder · doofinder · CWE-601 | Medium6.1 | — | 0.5% | Dec 19, 2023 |
24Monitor | CVE-2023-49185No exploit | WordPress Doofinder for WooCommerce Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS)doofinder · doofinder · CWE-79 | Medium6.1 | — | 0.4% | Dec 15, 2023 |
19Monitor | CVE-2024-25596No exploit | WordPress Doofinder for WooCommerce plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerabilitydoofinder · doofinder · CWE-79 | Medium4.8 | — | 0.3% | Mar 15, 2024 |
- CVE-2023-5167826Monitor
WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Control
MediumCVSS 6.5No exploitEPSS 0%doofinder · doofinderJan 5, 2024
- CVE-2023-4060224Monitor
WordPress Doofinder for WooCommerce Plugin <= 1.5.49 is vulnerable to Open Redirection
MediumCVSS 6.1No exploitEPSS 0%doofinder · doofinderDec 19, 2023
- CVE-2023-4918524Monitor
WordPress Doofinder for WooCommerce Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%doofinder · doofinderDec 15, 2023
- CVE-2024-2559619Monitor
WordPress Doofinder for WooCommerce plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%doofinder · doofinderMar 15, 2024