PT-2026-68870 · WordPress · Ajax Search Lite

·

CVE-2026-16258

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ajax Search Lite versions prior to 4.14.5
Description An issue exists where the software fails to prevent the deserialization of untrusted input, enabling unauthenticated attackers to perform PHP Object Injection. This occurs via the Search Statistics REST endpoint. If a suitable POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is present, this can be leveraged to achieve Remote Code Execution.
Recommendations Update Ajax Search Lite to version 4.14.5 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16258

Affected Products

Ajax Search Lite