Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16258: Ajax Search Lite < 4.14.5 - Unauthenticated Code Execution via Search Statistics

CVE-2026-16258 CVE-2026-16258
Summary

The Ajax Search Lite plugin for WordPress allows attackers to inject malicious code without a password. This can lead to unauthorized access and control of your website. Update the plugin to version 4.14.5 or higher to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
unknown ajax search lite < 4.14.5
Original title
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP...
Original description
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026