CVE-2023-51678
WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Doofinder Doofinder WP & WooCommerce Search. Este problema afecta a Doofinder WP & WooCommerce Search: desde n/a hasta 2.0.33.
The Doofinder for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'doofinder_reset_credentials' and 'doofinder_force_update_on_save' anonymous AJAX functions in versions up to, and including, 2.0.33. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset credentials and modify the update on save settings.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-21 CVE Reserved
- 2023-12-27 CVE Published
- 2024-01-10 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Doofinder Search vendor "Doofinder" | Doofinder Search vendor "Doofinder" for product "Doofinder" | <= 2.0.33 Search vendor "Doofinder" for product "Doofinder" and version " <= 2.0.33" | wordpress |
Affected
|