Description
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Published: 2026-08-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated PHP Object Injection is present in Ajax Search Lite plugin up to version 4.14.4. The vulnerability allows a malicious actor to craft specially formatted data that the plugin unserializes, leading to the creation of arbitrary PHP objects. This exploitation vector can enable code execution or unauthorized manipulation of application data. The weakness stems from the plugin's insecure handling of serialized input, which is why it is classified as CWE‑502.

Affected Systems

The affected product is the wpdreams Ajax Search Lite WordPress plugin, specifically versions 4.14.4 and all earlier releases.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the attack requires no authentication, meaning any web user can attempt exploitation. Although EPSS data is not available, the prevalence of the plugin in WordPress installations and the lack of a CISA KEV listing do not diminish the potential for widespread abuse. Prompt remediation is therefore essential to prevent remote code execution.

Generated by OpenCVE AI on August 6, 2026 at 16:16 UTC.

Remediation

Vendor Solution

Update the WordPress Ajax Search Lite plugin to the latest available version (at least 4.14.5).


OpenCVE Recommended Actions

  • Update the WordPress Ajax Search Lite plugin to version 4.14.5 or newer.
  • If an update cannot be applied immediately, deactivate or remove the Ajax Search Lite plugin to eliminate the immediate threat.
  • Monitor server logs for anomalous requests targeting the plugin’s input parameters and investigate any unauthorized activity.

Generated by OpenCVE AI on August 6, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Title WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:46:49.022Z

Reserved: 2026-02-25T12:14:18.579Z

Link: CVE-2026-28139

cve-icon Vulnrichment

Updated: 2026-08-06T14:46:45.455Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data