Impact
The Ajax Search Lite WordPress plugin prior to version 4.14.5 fails to validate or restrict input received by its Search Statistics REST endpoint, permitting the deserialization of crafted PHP objects. An attacker who can send the malicious payload to the endpoint can trigger a PHP Object Injection, and if a suitable POP chain exists in another installed instance of Ajax Search Lite or a related component, the attacker can achieve Remote Code Execution. This vulnerability therefore compromises the entire host, allowing an unauthenticated adversary to execute arbitrary code and potentially gain full control of the server.
Affected Systems
Any WordPress installation that has Ajax Search Lite installed with a version older than 4.14.5 is vulnerable. The exact vendor is listed as Unknown: Ajax Search Lite, and version information is not enumerated beyond the pre‑4.14.5 threshold. Admins should review installed plugin versions and upgrade if within the affected range.
Risk and Exploitability
The CVSS score is not provided, but the absence of an EPSS value and its lack of listing in CISA KEV suggest no widespread exploitation traffic has been observed to date. However, the vulnerability permits unauthenticated remote exploitation via a REST endpoint, meaning privileged access is not a prerequisite. Attackers can leverage known PHP Object Injection techniques to trigger Remote Code Execution once a POP chain is present, making the risk significant for any impacted site. Immediate patching is advised to mitigate this high‑impact threat.
OpenCVE Enrichment