CVE

CVE-2026-16258 — Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.14.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16258 Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.14.5 Deserialization of Untrusted Data Unknown < 4.14.5 4.14.5 2026-08-03

CVE-2026-16258

Ajax Search Lite for WordPress versions prior to 4.14.5 are vulnerable to PHP Object Injection due to untrusted input deserialization, which can be exploited by attackers without authentication. If a suitable PHP Object Persistence (POP) chain is present in another version of the same plugin or a related one, this vulnerability could lead to Remote Code Execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.