The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 22 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fibosearch
Fibosearch fibosearch Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-200 CWE-284 |
|
| Vendors & Products |
Fibosearch
Fibosearch fibosearch Wordpress Wordpress wordpress |
Sat, 22 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details. | |
| Title | FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-22T06:00:16.136Z
Reserved: 2026-07-22T14:35:43.427Z
Link: CVE-2026-16612
No data.
Status : Received
Published: 2026-08-22T06:16:15.130
Modified: 2026-08-22T06:16:15.130
Link: CVE-2026-16612
No data.
OpenCVE Enrichment
Updated: 2026-08-22T07:30:17Z