๐Ÿ” CVE Alert

CVE-2026-16612

UNKNOWN 0.0

FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.

Vendor unknown
Product fibosearch
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown fibosearch

Be the first to know when new unknown vulnerabilities affecting unknown fibosearch are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / FiboSearch
0 < 1.34.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/705cf14a-2782-408a-80b1-be7a9da6bbdd/

Credits

Duy Tran WPScan