Back

MEDIUM

FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure

Published Aug 22, 2026

Description

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 22, 2026
Updated Aug 23, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Aug 23, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Aug 22, 2026
Updated Aug 23, 2026
Exploited since n/a
EUVD-2026-64217