CVE · Medium

CVE-2025-48086 — Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.13.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-48086 Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.13.4 Deserialization of Untrusted Data Medium 5.5 < 4.13.4 4.13.4 2025-10-21

CVE-2025-48086

The Ajax Search Lite plugin for WordPress versions 4.13.3 and earlier is susceptible to PHP Object Injection due to improper handling of deserialized input. Authenticated users with administrator privileges can exploit this vulnerability by injecting a PHP object. While no specific Post-Object-Persistence (POP) chain is identified in the plugin itself, if such a chain exists through other installed plugins or themes, attackers could potentially delete files, access sensitive data, or run arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.