CVE-2025-47444: WordPress FiboSearch plugin <= 1.32.1 - Broken Access Control vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows Retrieve Embedded Sensitive Data.This issue affects GiveWP: from n/a before 4.6.1.
Other sources
Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiboSearch: from n/a through <= 1.32.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47444?
CVE-2025-47444 is classified as a critical vulnerability due to its potential to expose sensitive data.
How do I fix CVE-2025-47444?
To remediate CVE-2025-47444, upgrade your Liquid Web GiveWP and WordPress GiveWP Plugin to version 4.6.1 or later.
What types of sensitive information could be exposed by CVE-2025-47444?
CVE-2025-47444 could lead to the exposure of sensitive data embedded within sent data, potentially including user personal information.
Which versions of GiveWP are affected by CVE-2025-47444?
CVE-2025-47444 affects all versions of GiveWP prior to version 4.6.1.
Is there a CVE fix available for CVE-2025-47444?
Yes, a fix for CVE-2025-47444 is available in version 4.6.1 and later of the GiveWP plugin.