CRITICAL 9.8 NVD
CVE-2026-16258
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
References
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-07 via NVD.
Risk Timeline
CVE Disclosed2026-08-07 · 2 days ago
Remediation Resources
Official Advisory
wpscan.com/vulnerability/8487a2ce-cb4d-46b8-942e-334ac94cf115/
vulnfeed aggregates 9044 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.