CVSS
9.8
CVSS v3.1
EPSS
0.5%
Exploit Prediction Score
Published
August 7, 2026
Exploitability
EPSS probability 0.5%
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).