Description
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
Published: 2026-08-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ajax Search Lite WordPress plugin prior to version 4.14.5 fails to validate or restrict input received by its Search Statistics REST endpoint, permitting the deserialization of crafted PHP objects. An attacker who can send the malicious payload to the endpoint can trigger a PHP Object Injection, and if a suitable POP chain exists in another installed instance of Ajax Search Lite or a related component, the attacker can achieve Remote Code Execution. This vulnerability therefore compromises the entire host, allowing an unauthenticated adversary to execute arbitrary code and potentially gain full control of the server.

Affected Systems

Any WordPress installation that has Ajax Search Lite installed with a version older than 4.14.5 is vulnerable. The exact vendor is listed as Unknown: Ajax Search Lite, and version information is not enumerated beyond the pre‑4.14.5 threshold. Admins should review installed plugin versions and upgrade if within the affected range.

Risk and Exploitability

The CVSS score is not provided, but the absence of an EPSS value and its lack of listing in CISA KEV suggest no widespread exploitation traffic has been observed to date. However, the vulnerability permits unauthenticated remote exploitation via a REST endpoint, meaning privileged access is not a prerequisite. Attackers can leverage known PHP Object Injection techniques to trigger Remote Code Execution once a POP chain is present, making the risk significant for any impacted site. Immediate patching is advised to mitigate this high‑impact threat.

Generated by OpenCVE AI on August 7, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ajax Search Lite to version 4.14.5 or newer.
  • If an upgrade is unavailable, disable the Search Statistics REST endpoint or block unauthenticated access to it.
  • Remove Ajax Search Lite entirely if the functionality is no longer required and monitor the site for suspicious activity.

Generated by OpenCVE AI on August 7, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
Title Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T06:00:13.815Z

Reserved: 2026-07-20T08:27:28.711Z

Link: CVE-2026-16258

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T07:30:09Z

Weaknesses

No weakness.