Medium 5.4
2025-12-20< 1.32.1
CVE-2025-14298
Minimum safe version
1.32.1
Update to 1.32.1 or later to address 8 fixable vulnerabilities
CVE-2025-14298
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress FiboSearch – Ajax Search for WooCommerce Plugin < 1.25.0 is vulnerable to Cross Site Scripting (XSS)
WordPress FiboSearch – Ajax Search for WooCommerce Plugin <= 1.23.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2022-1469
WordPress FiboSearch – Ajax Search for WooCommerce plugin < 1.17.0 - Sensitive Information Disclosure vulnerability
WordPress FiboSearch – Ajax Search for WooCommerce plugin < 1.17.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability