Impact
Unauthenticated PHP Object Injection is present in Ajax Search Lite plugin up to version 4.14.4. The vulnerability allows a malicious actor to craft specially formatted data that the plugin unserializes, leading to the creation of arbitrary PHP objects. This exploitation vector can enable code execution or unauthorized manipulation of application data. The weakness stems from the plugin's insecure handling of serialized input, which is why it is classified as CWE‑502.
Affected Systems
The affected product is the wpdreams Ajax Search Lite WordPress plugin, specifically versions 4.14.4 and all earlier releases.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the attack requires no authentication, meaning any web user can attempt exploitation. Although EPSS data is not available, the prevalence of the plugin in WordPress installations and the lack of a CISA KEV listing do not diminish the potential for widespread abuse. Prompt remediation is therefore essential to prevent remote code execution.
OpenCVE Enrichment