Impact
FiboSearch, a WordPress plugin, has a flaw where password‑protected products are not consistently excluded from two unauthenticated AJAX endpoints. An attacker can trigger the autocomplete search endpoint (dgwt_wcas_ajax_search) or the details panel endpoint (dgwt_wcas_result_details) to obtain names, descriptions, and other metadata of products that are otherwise hidden behind a password. The result is a pure data disclosure with no privilege escalation or code execution.
Affected Systems
The vulnerability affects any WordPress installation running the FiboSearch plugin prior to version 1.34.1. The specific vendor is listed as Unknown:FiboSearch, and the affected product is the plugin itself. No further product versions are identified in the advisory.
Risk and Exploitability
Because the endpoints are reachable without authentication, the attack vector is a simple HTTP request to a publicly accessible AJAX URL. No patch or exploit is currently listed in KEV, and the EPSS score is not available, so exploitation likelihood is unquantified, but the ease of the attack suggests that any site with the vulnerable plugin exposed is susceptible to automated enumeration of protected product data.
OpenCVE Enrichment