Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-16258: Ajax Search Lite < 4.14.5 - Unauthenticated Code Execution via Search Statistics
CVE-2026-16258
CVE-2026-16258
Summary
The Ajax Search Lite plugin for WordPress allows attackers to inject malicious code without a password. This can lead to unauthorized access and control of your website. Update the plugin to version 4.14.5 or higher to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | ajax search lite | < 4.14.5 |
Original title
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP...
Original description
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026