CVE-2026-16258
Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
| Vendor | unknown |
| Product | ajax search lite |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ajax search lite
Be the first to know when new unknown vulnerabilities affecting unknown ajax search lite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Ajax Search Lite
0 < 4.14.5
References
Credits
Jakub Herman WPScan