CVE-2026-16612
Received Received - Intake

FiboSearch Plugin Password-Protected Product Disclosure

Vulnerability report for CVE-2026-16612, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: WPScan

Description

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dgwt fibosearch to 1.34.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16612 is a vulnerability in the FiboSearch WordPress plugin before version 1.34.1. It allows unauthenticated users to access password-protected product information without the password through two AJAX endpoints: the autocomplete search endpoint and the Details Panel endpoint when queried for taxonomy details.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the FiboSearch plugin version before 1.34.1. You can verify the plugin version by inspecting the plugin files or WordPress admin panel. Test the affected endpoints by sending unauthenticated requests to dgwt_wcas_ajax_search and dgwt_wcas_result_details to see if password-protected product information is disclosed.

Impact Analysis

This vulnerability could allow attackers to enumerate and disclose sensitive information about password-protected products, including their metadata, without proper authorization. This may lead to unauthorized access to confidential product details.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing sensitive product information without authentication. Unauthorized access to password-protected products may lead to unauthorized disclosure of personal or sensitive data, violating data protection requirements under these regulations.

Mitigation Strategies

Immediately update the FiboSearch plugin to version 1.34.1 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review access logs for suspicious requests to the affected endpoints to identify potential exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16612. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart