The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.
We have discovered 34,360 live websites that are affected by CVE-2026-16612.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 34,360 live websites (100% of Ajax Search For Woocommerce install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 54 versions ( 100% of all versions) |
| 7,776 websites | |
| 2,091 websites | |
| 1,797 websites | |
| 1,634 websites | |
| 1,630 websites | |
| 1,375 websites | |
| 1,209 websites | |
| 1,178 websites | |
| 1,170 websites | |
| 1,076 websites |
| .com | 13,200 websites |
| .com.br | 1,356 websites |
| .co.uk | 1,128 websites |
| .nl | 1,059 websites |
| .de | 917 websites |
| .pl | 884 websites |
| .it | 874 websites |
| .ru | 844 websites |
| .es | 794 websites |
| .fr | 700 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********************.fr | **,*** | ||
| *************.fr | **,*** | ||
| *********.com | **,*** | ||
| **********.com | **,*** | ||
| ********.com | **,*** | ||
| **********.de | **,*** | ||
| ********.com | **,*** | ||
| **********.**.il | **,*** | ||
| ********.**.il | **,*** | ||
| *******.**.il | **,*** |
FAQ