PT-2024-14236 · Doofinder · Doofinder Wp & Woocommerce Search

Abdi Pranata

·

Published

2024-01-05

·

Updated

2024-01-10

·

CVE-2023-51678

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Doofinder WP & WooCommerce Search versions 2.0.33 and earlier

Description:

The issue is a Cross-Site Request Forgery (CSRF) vulnerability. This type of vulnerability allows an attacker to trick a user into performing unintended actions on a web application that the user is authenticated to.

Recommendations:

For Doofinder WP & WooCommerce Search versions 2.0.33 and earlier, update to a version later than 2.0.33 to resolve the issue.

As a temporary workaround, consider implementing additional CSRF protection measures, such as token-based validation, to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-51678

Affected Products

Doofinder Wp & Woocommerce Search