CVE · Medium

CVE-2022-1469 — FiboSearch – Ajax Search for WooCommerce [ajax-search-for-woocommerce] < 1.18.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1469 FiboSearch – Ajax Search for WooCommerce [ajax-search-for-woocommerce] < 1.18.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.18.0 1.18.0 2022-05-16

CVE-2022-1469

The FiboSearch plugin before version 1.18.0 fails to properly sanitize and escape certain configuration options, creating a vulnerability where administrators and other high-privilege users can inject malicious scripts that persist in the database when the unfiltered_html capability is restricted. This stored cross-site scripting flaw enables attackers with elevated access to execute arbitrary JavaScript in the context of other users' sessions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.