CVE-2025-48086: WordPress Ajax Search Lite plugin <= 4.13.3 - PHP Object Injection vulnerability
Published Nov 6, 2025
·Updated
Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.
Affected Software
2 affected components
wpdreams Ajax Search Lite<=4.13.3
WordPress Ajax Search Lite<=4.13.3
Event History
Nov 6, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Feb 22, 58291
Event
via MITRE·11:46 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48086?
The severity of CVE-2025-48086 is considered high due to the potential for object injection from deserialization of untrusted data.
2
How do I fix CVE-2025-48086?
To fix CVE-2025-48086, update the Ajax Search Lite plugin to a version later than 4.13.3.
3
What versions are affected by CVE-2025-48086?
CVE-2025-48086 affects Ajax Search Lite versions from n/a through 4.13.3.
4
What type of vulnerability is CVE-2025-48086?
CVE-2025-48086 is a deserialization of untrusted data vulnerability that allows for object injection.
5
Which applications are impacted by CVE-2025-48086?
CVE-2025-48086 impacts the wpdreams Ajax Search Lite and WordPress Ajax Search Lite plugins.