CyberRota Analysis
AI-GeneratedThe FiboSearch plugin for WordPress prior to version 1.34.1 has a vulnerability that allows unauthenticated users to access and enumerate password-protected products and their metadata through specific AJAX endpoints. This exposure can lead to unauthorized disclosure of sensitive product information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.
Original NVD Description
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.