CVE-2026-16258 PUBLISHED

Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint

Assigner: WPScan
Reserved: 20.07.2026 Published: 07.08.2026 Updated: 07.08.2026

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.

Product Status

Vendor Unknown
Product Ajax Search Lite
Versions Default: unaffected
  • affected from 0 to 4.14.5 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE