CVE-2026-16258: Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Ajax Search Liteto a version that resolves this vulnerability.Fixed in 4.14.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16258?
CVE-2026-16258 has a risk score of 80, indicating a high severity level.
How do I fix CVE-2026-16258?
To fix CVE-2026-16258, upgrade the Ajax Search Lite WordPress plugin to version 4.14.5 or later.
What does CVE-2026-16258 exploit?
CVE-2026-16258 exploits the lack of input validation in the Search Statistics REST Endpoint, which allows for PHP Object Injection.
Can CVE-2026-16258 be exploited without authentication?
Yes, CVE-2026-16258 can be exploited by unauthenticated attackers.
What should I do if I cannot update Ajax Search Lite due to compatibility issues?
If you cannot update Ajax Search Lite, consider disabling the plugin temporarily or implementing strict access controls to mitigate the risk of CVE-2026-16258.