Impact
The Ajax Search Lite WordPress plugin prior to version 4.14.5 fails to restrict or sanitize input received by its Search Statistics REST endpoint, allowing an attacker to send crafted data that the server unserializes. This deserialization flaw supports PHP Object Injection, and if an appropriate population‑of‑pointer (POP) chain is present in another installed copy of Ajax Search Lite before 4.14.5 or in a component not specified in the CVE, the attacker can trigger Remote Code Execution. The vulnerability is exploitable without credentials and can compromise the entire host. The vulnerability lists CWE‑502, indicating it is an insecure deserialization weakness.
Affected Systems
Any WordPress site that has Ajax Search Lite installed with a version older than 4.14.5 is at risk. The vendor is marked as Unknown: Ajax Search Lite. No further version details are provided beyond the pre‑4.14.5 cutoff, so administrators should verify the installed plugin version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 9.8 denotes a critical severity, while the EPSS score of < 1% and its absence from the CISA KEV catalog suggest limited publicly known exploitation. However, because the flaw is reachable via an unauthenticated REST endpoint, privileged access is not required. The risk remains significant for any site with the affected plugin, and the potential for Remote Code Execution demands prompt mitigation.
OpenCVE Enrichment