CVE-2026-28139: WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
Published Aug 6, 2026
·Updated
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Affected Software
1 affected component
WordPress Ajax Search Lite<=4.14.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ajax Search Lite pluginto a version that resolves this vulnerability.Fixed in 4.14.5
Event History
Aug 6, 2026
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
RemedyDescriptionSeverityWeakness