Digireturn's vulnerability footprint encompasses a small set of WordPress plugins and extensions, including DN Popup, Footer Contacts Bar, and Shipping by Weight for WooCommerce, that extend e-commerce and site functionality for small-to-medium web deployments. The observed weakness classes center on web-application input handling, with recurring findings in cross-site request forgery and cross-site scripting that are characteristic of plugin-layer integration points. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digireturn over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11842MEDIUM The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in | Dec 27, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-7690MEDIUM The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CS | Sep 2, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-3410MEDIUM The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross | Jul 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digireturn.
Media articles that mention a CVE ID that affects a product developed by Digireturn — matched by CVE ID, not by vendor name.