Executive brief
Doofinder for WooCommerce is a WordPress plugin used to integrate advanced search functionality into online stores. A security flaw in this plugin allows sensitive information to be inadvertently included in data sent by the website, potentially exposing internal details to unauthorized users. This could lead to the exposure of configuration data or other sensitive information that could be used to facilitate further attacks against the store.
Technical details
The Doofinder for WooCommerce plugin for WordPress is vulnerable to sensitive data exposure (CWE-201) in versions up to and including 2.10.13. The vulnerability stems from the improper insertion of sensitive information into data sent by the application, allowing unauthenticated remote attackers to retrieve embedded sensitive data. This is a low-complexity attack that does not require user interaction. The issue was addressed in version 2.10.14.
Affected products
- Doofinder Doofinder for WooCommerce <= 2.10.13
Timeline
- 2026-02-11: other: Vulnerability reported by researcher
- 2026-03-13: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published to NVD
- 2026-06-17: patched: Patch confirmed available in version 2.10.14