Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Reflected XSS.This issue affects FiboSearch: from n/a through 1.34.1.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Client‑side script execution via reflected XSS
Action: Immediate Patch
AI Analysis

Impact

The FiboSearch plugin for WordPress contains an improper neutralization of input that allows reflected cross‑site scripting through its ajax‑search‑for‑woocommerce feature. The flaw permits an attacker to inject scripts into the web page that is rendered for a victim, potentially leading to cookie theft, session hijacking, defacement, or malicious content delivery. This does not grant server‑side access but can compromise the integrity and confidentiality of the victim’s session and data viewed within the browser.

Affected Systems

WordPress sites that have installed the Damian Góra FiboSearch plugin version 1.34.1 or earlier are affected. The vulnerability is present in all releases from the initial version up to and including 1.34.1.

Risk and Exploitability

Based on the description, it is inferred that attackers can exploit the flaw remotely by sending crafted requests that the search function reflects without proper escaping. The CVSS score of 7.1 indicates a high severity impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. A successful exploitation would allow arbitrary script execution in the context of a victim’s browser, potentially enabling credential theft or malicious activity within the user’s session.

Generated by OpenCVE AI on October 9, 2026 at 12:30 UTC.

Remediation

Vendor Solution

Update the WordPress FiboSearch plugin to the latest available version (at least 1.34.2).


OpenCVE Recommended Actions

  • Upgrade the FiboSearch plugin to version 1.34.2 or later.
  • If an upgrade is not feasible, disable or remove the FiboSearch plugin from the WordPress installation until a patch is applied.
  • Review any custom templates or scripts that interact with the search functionality and ensure all user‑controlled input is properly escaped or sanitized before rendering.

Generated by OpenCVE AI on October 9, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Reflected XSS.This issue affects FiboSearch: from n/a through 1.34.1.
Title WordPress FiboSearch plugin <= 1.34.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:16.406Z

Reserved: 2026-09-23T13:00:19.280Z

Link: CVE-2026-96553

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:45.420

Modified: 2026-10-09T10:16:45.420

Link: CVE-2026-96553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')