CVE-2026-16612

FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.


We have discovered 34,360 live websites that are affected by CVE-2026-16612.

Run a Free Instant Scan




Affected Software

Product  Ajax Search For Woocommerce
Category Wordpress Plugins
Vulnerable Domains34,360 live websites (100% of Ajax Search For Woocommerce install base)
Vulnerable Versions
  • from 0 through 1.34.1
Vulnerable Versions Count54 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 22, 2026
  • Updated - Aug 23, 2026

Credits

  • Duy Tran (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16612
United States7,776 websites



Germany2,091 websites
Spain1,797 websites
GB1,634 websites
France1,630 websites
Brazil1,375 websites
Italy1,209 websites
Poland1,178 websites
Netherlands1,170 websites
Russia1,076 websites

Website Distribution by TLD

Number of websites using CVE-2026-16612
.com13,200 websites
.com.br1,356 websites
.co.uk1,128 websites
.nl1,059 websites
.de917 websites
.pl884 websites
.it874 websites
.ru844 websites
.es794 websites
.fr700 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16612

Top websites that are affected by CVE-2026-16612. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.fr France**,***
*************.fr France**,***
*********.com United States**,***
**********.com United States**,***
********.com United States**,***
**********.de Germany**,***
********.com United States**,***
**********.**.il Israel**,***
********.**.il Israel**,***
*******.**.il Israel**,***
See full domain list

FAQ

CVE-2026-16612 is Exposure of Sensitive Information to an Unauthorized Actor in Ajax Search For Woocommerce
A total of 34,360 websites have been identified as vulnerable to CVE-2026-16612, based on global website indexing conducted by WebTechSurvey.
The Ajax Search For Woocommerce is affected by the CVE-2026-16612 vulnerability.
Ajax Search For Woocommerce versions up to 1.34.1 are vulnerable to CVE-2026-16612.
CVE-2026-16612 is resolved in version 1.34.1 of Ajax Search For Woocommerce.