CVE-2025-48086
The Ajax Search Lite plugin for WordPress versions 4.13.3 and earlier is susceptible to PHP Object Injection due to improper handling of deserialized input. Authenticated users with administrator privileges can exploit this vulnerability by injecting a PHP object. While no specific Post-Object-Persistence (POP) chain is identified in the plugin itself, if such a chain exists through other installed plugins or themes, attackers could potentially delete files, access sensitive data, or run arbitrary code.
Based on public CVE data (MITRE/NVD).