Impact
The FiboSearch plugin for WordPress contains an improper neutralization of input that allows reflected cross‑site scripting through its ajax‑search‑for‑woocommerce feature. The flaw permits an attacker to inject scripts into the web page that is rendered for a victim, potentially leading to cookie theft, session hijacking, defacement, or malicious content delivery. This does not grant server‑side access but can compromise the integrity and confidentiality of the victim’s session and data viewed within the browser.
Affected Systems
WordPress sites that have installed the Damian Góra FiboSearch plugin version 1.34.1 or earlier are affected. The vulnerability is present in all releases from the initial version up to and including 1.34.1.
Risk and Exploitability
Based on the description, it is inferred that attackers can exploit the flaw remotely by sending crafted requests that the search function reflects without proper escaping. The CVSS score of 7.1 indicates a high severity impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. A successful exploitation would allow arbitrary script execution in the context of a victim’s browser, potentially enabling credential theft or malicious activity within the user’s session.
OpenCVE Enrichment